T08 · Insecure Dependencies
- Location
SKILL.md:15- Finding
Unpinned Global Installation of a Mutable npm Dependency
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This AdsPower skill matches its stated purpose, but it can access session cookies, API keys, credentials, and destructive profile operations without enough safeguards.
Install only if you trust the adspower-browser npm package and understand that this skill can operate on real AdsPower profiles, cookies, proxies, account credentials, and profile-sharing targets. Pin and verify the CLI version, avoid passing API keys directly on command lines, and require explicit confirmation before delete, cache-clear, close-all, cookie-export, or share operations.
SKILL.md:15Unpinned Global Installation of a Mutable npm Dependency
SKILL.md:47AdsPower API Keys Exposed Through Command-Line Arguments
YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).
�� `toolIntentMetadata.ts` 同源)。 | 根据用户自然语言选择对应 CLI 命令或 MCP 工具(尤其 `open-browser`)。 |
| [references/browser-profile-management.md](references/browser-profile-management.md) | **open-browser**, **close-browser**, **create-browser**, **update-browser**, **delete-browser**, **get-browser-list**, **get-opened-browser**, **move-browser**, **get-profile-cookies**, **get-profile-ua**, **close-all-profiles**, **new-fingerprint**, **delete-cache-v2**, **share-profile**, **get-browser-active**, **get-cloud-active** parameters. | Any browser profile operation (open, create, update, delete, list, move, cookies, UA, cache, share, status). |
| [references/group-management.md](references/group-management.md) | **create-group**, **update-group**, **get-group-list** parameters. | Creating, updating, or listing browser groups. |
| [references/application-management.md](references/application-management.md) | **check-status**, **get-application-list** par
The 'close-all-profiles' entry is mapped to vague, high-risk phrases like 'close everything' and 'stop all browsers', which can easily match ambiguous user intent. Because this action is destructive to current sessions, accidental routing could terminate all open AdsPower profiles and disrupt automation, user workflows, or active account activity.
Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.
| `get-profile-ua` | Get User-Agent strings for up to 10 profiles. | 批量查询最多 10 个 profile 的 UA。 | user agent, UA string, browser UA | UA,用户代理,浏览器标识 |
| `close-all-profiles` | Close all opened profiles on this device. | 关闭本机所有已打开的环境。 | close everything, stop all browsers, shutdown all profiles | 全部关闭,一键关环境,关所有浏览器 |
| `new-fingerprint` | Generate a new fingerprint for up to 10 profiles. | 为最多 10 个 profile 重新生成指纹。 | refresh fingerprint, regenerate fp, new device identity | 刷新指纹,重新指纹,换设备指纹 |
| `delete-cache-v2` | Clear selected local cache types for profiles. | 按类型清理 profile 本地缓存。 | clear cache, wipe storage, delete history cache | 清缓存,删历史,清理本地数据 |
| `share-profile` | Share profiles to another AdsPower account. | 将 profile 分享给其他 AdsPower 账号。 | share account, transfer profile, send browser to user | 分享环境,转让profile,发给同事 |
| `get-browser-active` | Get active status/details for one profile. | 查询单个 profile 的活跃/运行信息。 | is profile running, active status, browser state | 是否在线,活跃状态,运行信息 |
| `get-cloud-active` | Query cloud-side active status for many profile IDs. | 按 user_ids 批量查询云端活跃状态。 | cloud status, remote active, team multi device caveat | 云端状态,远程是否打开,多设备模式限制 |
The metadata description contains broad trigger phrases like opening environments, profiles, proxies, or AdsPower generally, which can cause the skill to activate on loosely related user requests. Overbroad activation increases the chance that a high-privilege operational skill is invoked when the user did not clearly request profile management actions.
The skill instructs use of npx adspower-browser, which resolves and executes the latest package version unless explicitly pinned. That creates a supply-chain risk: a malicious or compromised upstream release could be pulled at runtime and executed in the user's environment.
The when-to-use section includes ambiguous activation guidance, including multilingual shorthand and broad references to browsers, profiles, fingerprint, UA, or proxy. In context, this skill can perform profile creation, deletion, cookie retrieval, and other sensitive operations, so ambiguous routing makes unintended execution more dangerous.
The skill documents destructive commands such as deleting profiles, tags, proxies, and cache, but does not warn about irreversible data loss or recommend confirmation. An agent using this guidance could execute high-impact state-changing actions without ensuring the user understands the consequences.
This markdown file documents a delete-browser action that deletes browser profiles, but it provides no warning that the operation may be destructive or irreversible. Under the markdown-specific warning criteria, actions affecting user data should include a clear warning about impact and recovery expectations.
Documenting direct cookie retrieval without any privacy or authorization guardrail is more security-sensitive than ordinary profile-management actions because cookies can grant authenticated session access. In this skill context, browser-profile automation increases the chance that operators handle many accounts, so exposing cookie export capability without warnings or access constraints raises account-takeover and data-exfiltration risk.
The delete-cache-v2 action clears local storage, IndexedDB, cookies, history, and other cached data, which directly affects user data and browsing state. Although it notes that browsers should not be open, it does not clearly warn about data removal consequences such as sign-outs or loss of local state.
The share-profile command sends profile information to an email address or phone number, which has privacy implications and may expose data outside the current account boundary. The description does not warn users about verifying recipients or the sensitivity of shared fields.
The documentation exposes a destructive operation, delete-tag, without any warning that it permanently removes tags or guidance to verify the target IDs before execution. In an agent skill context, sparse docs around destructive actions can cause accidental data loss because an LLM or user may invoke deletion based only on a high-level request, without understanding consequences or confirming scope.
This markdown file begins with a Chinese title and usage instructions, which effectively forces a specific language for users consuming the skill documentation. The policy allows locale constraints only when users are given a choice or the restriction is clearly documented and justified, which is not present here.
This markdown file documents operations that can create, update, and delete proxy records and accepts sensitive fields such as usernames and passwords. Under the markdown-specific warning criteria, it should disclose privacy or system-impact implications, but no warning is present anywhere in the description.
The trigger map includes generic phrases such as 'open browser', 'list profiles', and 'new page' that can plausibly appear in ordinary user requests outside this skill’s intended scope. In an intent-routing system, overly broad triggers can cause accidental invocation of AdsPower actions, leading to unintended profile operations or browser automation on the local machine.
The open-browser documentation includes options to enable password filling and password saving, both of which affect stored credentials and authentication behavior. The file does not warn users that these settings may expose or persist sensitive credentials in the launched browser environment.
Most of the file is in English, but the platform_account subfield description includes Chinese text (domain_name 和 login_user 必填,password / fakey 可选). This inconsistency can create a language accessibility issue for users who are not expecting or able to read that language, and no language choice or justification is provided.
The close-all-profiles command affects all opened browser profiles on the current device, which can disrupt active sessions or ongoing work. The description states what it does but does not warn users about the scope and impact of the action.
No suspicious patterns detected.