Back to skill

Security audit

Browser Auto Plus

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a browser automation guide, but it includes under-scoped anti-detection, proxy, and CAPTCHA-bypass guidance that users should review carefully.

Install only if you will use it for sites and accounts you are authorized to automate. Pin Playwright through a project manifest and lockfile before running install commands, and avoid using the anti-detection, proxy rotation, or CAPTCHA-avoidance guidance to bypass site protections.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:27
Finding

Unpinned Playwright Package Execution Through npx

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 27–33
Vulnerability Type: Unpinned third-party dependency execution
Risk Level: Medium

bash
# Check available browsers
npx playwright install

# Or install specific browser
npx playwright install chromium
npx playwright install firefox
npx playwright install webkit

Technical Analysis

The setup instructions invoke playwright through npx without specifying an exact reviewed package version, requiring a committed lockfile, or preventing network installation. When a trusted local Playwright executable is unavailable, npx may resolve and download the package from the configured npm registry before executing it.

This creates a supply-chain exposure because the code executed depends on registry state and local npm configuration at invocation time rather than a dependency version fixed during review. A compromised package release, maintainer account, registry, mirror, or dependency-resolution configuration could cause attacker-controlled package code to run. The Playwright installation process also retrieves browser artifacts, expanding the externally sourced execution and installation surface.

Attack Path

  1. A user follows the documented setup instructions on a system without a trusted local Playwright installation.
  2. The user runs an unpinned command such as npx playwright install.
  3. npx resolves the package using the configured npm registry and current dependency metadata.
  4. An attacker has compromised a resolved package release, dependency, maintainer account, registry path, or configured mirror.
  5. The malicious package or dependency is downloaded and executed under the invoking user's account.
  6. The attacker can perform actions permitted to that account while the expected browser installation appears to proceed.

Impact Assessment

Successful exploitation could provide arbitrary code execution with the privileges of the user running npx. The affected sco ...[truncated 567 chars]

Remediation
View remediation

Remediation Suggestions

  1. Declare Playwright at an exact reviewed version in a committed package manifest rather than resolving it implicitly:
    json
    {
      "devDependencies": {
        "playwright": "1.x.y"
      }
    }
    
  2. Commit the generated lockfile and review dependency changes before upgrades.
  3. Use npm ci in clean environments so installation follows the committed lockfile.
  4. Invoke only the installed local executable and prohibit fallback downloads:
    bash
    npm ci
    npx --no-install playwright install chromium
    
  5. Pin and authenticate the npm registry configuration, and use registry integrity metadata and dependency scanning.
  6. Run installation as an unprivileged user in an isolated environment with restricted filesystem access, network access, and credentials.
  7. Pin or otherwise verify downloaded browser artifacts where supported, and document the expected package and browser versions.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The skill promotes proxy use for anonymity together with web scraping, but does not provide a clear warning about legal, privacy, terms-of-service, or target-system impact. In context, this omission makes potentially abusive or evasive activity easier to operationalize and lowers friction for misuse against third-party sites.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The skill instructs users to run npx playwright install without pinning a specific package version, which can pull whatever version is current at execution time. This creates a supply-chain and reproducibility risk: a compromised, malicious, or breaking upstream release could be executed in the user's environment unexpectedly.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

Using npx playwright install chromium without version pinning causes the command to resolve and execute the latest available package at runtime. In automation-focused skills, this is particularly risky because users may copy-paste commands into privileged developer environments, exposing them to supply-chain compromise or unstable behavior.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The unpinned npx playwright install firefox command executes an upstream package version that is not controlled by the skill author or user. That makes the skill non-reproducible and increases the chance of accidental execution of a compromised or malicious release.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The command npx playwright install webkit is unpinned and therefore inherits the same supply-chain exposure as other floating npx installs. Because this skill is meant for broad reuse, leaving installation commands floating increases the blast radius if the dependency stream changes or is compromised.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill gives concrete CAPTCHA handling, proxy rotation, stealth, and anti-detection guidance without an explicit warning against bypassing site protections. In this browser-automation context, these instructions materially increase the capability to evade anti-bot defenses, facilitating unauthorized scraping, account abuse, or other policy-violating automation.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

Repeating the unpinned npx playwright install guidance in troubleshooting reinforces unsafe installation behavior and makes users more likely to execute a floating package. This perpetuates the same supply-chain and reproducibility risks elsewhere in the document.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.