Back to skill

Security audit

browser-auto-download

Security checks for vulnerabilities and agentic risk

Overview

This skill does what it says, but it can automatically click through webpages and save unverified executable downloads locally with limited safety controls.

Install only if you are comfortable with an agent-controlled browser visiting download pages and saving files to disk. Use a dedicated output folder, run it only on trusted URLs, inspect the final downloaded file, and verify publisher signatures or checksums before opening or installing anything. Avoid debug mode on authenticated, private, or sensitive pages unless you are prepared to manage the saved screenshots, HTML, and text files.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:237
Finding

Unpinned Playwright Dependency and Browser Installation

Content
View full analysis
Remediation
View remediation
\ --hash=sha256: ``` 2. Install dependencies using hash enforcement: ```bash pip install --require-hashes -r requirements.txt ``` 3. Document and pin the expected Playwright-managed Chromium revision. 4. Use a dependency-locking process and retain reviewed lockfiles in the repository. 5. Run dependency and artifact integrity checks in CI. 6. Establish a controlled update process in which dependency upgrades are explicitly reviewed, tested, and repinned. 7. Avoid installing the Skill or its dependencies from an elevated shell unless strictly necessary. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/auto_download.py:116
Finding

Unverified and Attacker-Influenceable Download Selection

Content
View full analysis
{href[:80]}", file=sys.stderr) ``` The script automatically attempts page-controlled candidate URLs: ```python for link_type, href, text, wait_time, elem_type in download_links[:10]: # Try top 10 try: print(f"Trying {link_type} ({elem_type}): {text[:50]}...", file=sys.stderr) if link_type == 'direct' and href: # Direct download link page.goto(href, wait_until="domcontentloaded") time.sleep(wait_time) elif link_type == 'onclick' and href: # Element with onclick handler try: # Try to find and click the element elem = page.locator(f"div[onclick*='{href[:30]}'], span[onclick*='{href[:30]}']").first if elem.count() > 0: elem.click() time.sleep(wait_time) ``` The resulting filename is accepted from the remote response and used directly in the destination path: ```python filename = download.suggested_filename print(f"Saving: {filename}", file=sys.stderr) save_path = os.path.join(output_dir, filename) download.save_as(save_path) download.delete() ``` ### Technical Analysis The visited webpage controls candidate URLs, v ...[truncated 2842 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (13)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The quickstart encourages automated downloading of files, including executable installers from external sites, without warning users that files will be written to disk or that downloaded binaries may be untrusted. In the context of an automation skill that intentionally navigates pages and triggers downloads, this omission increases the likelihood of unsafe use, accidental execution of malicious software, or silent persistence of unwanted files.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README explicitly markets automated downloading and saving of files, including executables and archives, but does not clearly warn users that the skill writes potentially untrusted binaries to the local filesystem. In an agent context, this can normalize fetching and storing installer payloads from third-party sites, increasing the risk of accidental execution or supply-chain exposure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documented behavior includes automated navigation, element discovery, and button clicking on external webpages, yet the README does not warn that these actions can trigger unintended or deceptive downloads. This is especially relevant because the skill is designed to handle dynamic pages and auto-downloads, so user expectations may underestimate how much remote page logic can influence outcomes.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill performs network access and writes downloaded files to the local filesystem, but the manifest does not declare any explicit tool scope or permissions. That omission weakens reviewability and user consent because the skill's operational capabilities are broader than what is formally advertised, increasing the chance of unintended or unsafe execution in agent frameworks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The documentation encourages automated downloading and local saving of platform-specific software, including executable installers, without prominent warnings about trust verification, checksum/signature validation, or the risks of saving untrusted binaries. In this context, the skill is more dangerous because it is specifically designed to follow dynamic web flows and capture auto-downloads, which can increase exposure to malicious or spoofed download targets.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The guide encourages a debug mode that stores screenshots, full HTML, and extracted text from visited pages, but it does not warn that these artifacts may contain sensitive data such as session state rendered in-page, personal information, internal URLs, or confidential business content. In a browser-automation download skill, users are likely to visit authenticated or vendor pages, which makes indiscriminate local capture more privacy-sensitive than ordinary logging.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The debug helper saves a screenshot, full HTML, and full page text for any visited URL into a local folder. In a browser automation skill that may be pointed at arbitrary pages, this can capture session-specific content, personal data, tokens embedded in the DOM, or internal pages unrelated to the file download itself, which exceeds the minimum data needed for troubleshooting.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Debug mode persists screenshots, full HTML, and extracted body text without warning that these artifacts may contain credentials, personal information, or confidential business data rendered in the browser. Because the tool navigates arbitrary pages and performs interactive actions, the captured artifacts can retain much more sensitive context than expected from a download utility.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The function defaults to writing downloaded files into the user's Downloads directory and can fetch arbitrary executables or archives from attacker-controlled URLs. Without an explicit warning, confirmation, or trust policy, this creates a social-engineering and unsafe file-placement risk, especially because the skill's purpose is specifically to automate acquisition of runnable binaries.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The natural-language content consistently forces a single language for user-facing instructions. Under the policy, a language restriction should either offer user choice or be explicitly justified as a locale-specific skill, which is not indicated here.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The package description says only "Intelligent browser-automated file downloads with multi-modal support," which describes a broad capability but does not specify concrete trigger phrases, scope boundaries, or exclusion conditions. In a manifest file, this kind of generic wording can overlap with many ordinary download-related requests and may lead to unintended invocation.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
88% confidence
Finding

The dependency uses a caret range (^1.40.0), which allows newer Playwright releases to be installed without a fully deterministic version selection. In a skill that automates browsers and downloads files, an unexpected vulnerable or behavior-changing dependency version can expand supply-chain risk and affect how untrusted web content is handled.

Content

Scanner excerpt · package.json (reported line 36)May include surrounding context.

json
"python": ">=3.8"
  },
  "dependencies": {
    "playwright": "^1.40.0"
  },
  "devDependencies": {},
  "openclaw": {

Unverifiable Dependency: playwright has 1 known advisory(ies) (CVE-2025-59288 (Playwright downloads and installs browsers without verifying the authenticity of)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
93% confidence
Finding

The manifest declares Playwright without pinning to an exact version, and the package has a cited advisory involving downloading and installing browsers without authenticity verification. Because this skill's core function is browser automation for downloading content from potentially untrusted sites, the dependency risk is especially relevant: compromised browser binaries or insecure browser acquisition could undermine the host environment.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.