Back to skill

Security audit

adspower-browser

Security checks for vulnerabilities and agentic risk

Overview

This AdsPower skill matches its stated purpose, but it can access session cookies, API keys, credentials, and destructive profile operations without enough safeguards.

Install only if you trust the adspower-browser npm package and understand that this skill can operate on real AdsPower profiles, cookies, proxies, account credentials, and profile-sharing targets. Pin and verify the CLI version, avoid passing API keys directly on command lines, and require explicit confirmation before delete, cache-clear, close-all, cookie-export, or share operations.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:15
Finding

Unpinned Global Installation of a Mutable npm Dependency

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:47
Finding

AdsPower API Keys Exposed Through Command-Line Arguments

Content
View full analysis
``` ```bash ads [] [--port PORT] [--api-key KEY] ``` ```bash AdsPower Global: Windows设备下: "AdsPower Global.exe" --headless=true --api-key=your_api_key --api-port=50325 MacOS设备下:"/Applications/AdsPower Global.app/Contents/MacOS/AdsPower Global" --args --headless=true --api-key=your_api_key --api-port=50325 Linux设备下:adspower_global --headless=true --api-key=your_api_key --api-port=50325 ``` The command is also repeated in the command summary: ```bash ads start -k # Start the adspower runtime ``` ### Technical Analysis The documentation recommends passing the AdsPower API key directly through `-k` or `--api-key`. Command-line secrets can be exposed through: - Shell history files - Process listings and process-inspection interfaces - Terminal session recording - Debugging and diagnostic output - Command auditing and endpoint monitoring - CI/CD job logs or wrapper-script logging The Skill also documents the `ADS_API_KEY` environment variable as an alternative. While this avoids placing the secret directly in the command line, environment variables may still be inherited by child processes or exposed through diagnostics. A protected credential store or restricted configuration file would provide stronger handling. The API key protects capabilities that include profile management, cookie retrieval, proxy configuration, profile sharing, browser startup, and destructive profile or cache operations. Exposure is consequently more significant than disclosure of a simple availability-check token. ### Attack Path 1. A user follows the documented example and supplies a real API key through `-k` or `--api-key`. 2. The command is retained in shell history, captured by l ...[truncated 1233 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (18)

YARA rule 'info_stealer': Information stealer patterns (credential harvesting, browser data theft) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · SKILL.md (reported line 223)May include surrounding context.

md
�� `toolIntentMetadata.ts` 同源)。 | 根据用户自然语言选择对应 CLI 命令或 MCP 工具(尤其 `open-browser`)。 |
| [references/browser-profile-management.md](references/browser-profile-management.md) | **open-browser**, **close-browser**, **create-browser**, **update-browser**, **delete-browser**, **get-browser-list**, **get-opened-browser**, **move-browser**, **get-profile-cookies**, **get-profile-ua**, **close-all-profiles**, **new-fingerprint**, **delete-cache-v2**, **share-profile**, **get-browser-active**, **get-cloud-active** parameters. | Any browser profile operation (open, create, update, delete, list, move, cookies, UA, cache, share, status). |
| [references/group-management.md](references/group-management.md) | **create-group**, **update-group**, **get-group-list** parameters. | Creating, updating, or listing browser groups. |
| [references/application-management.md](references/application-management.md) | **check-status**, **get-application-list** par

Vague Triggers

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The 'close-all-profiles' entry is mapped to vague, high-risk phrases like 'close everything' and 'stop all browsers', which can easily match ambiguous user intent. Because this action is destructive to current sessions, accidental routing could terminate all open AdsPower profiles and disrupt automation, user workflows, or active account activity.

Content

No source excerpt is available for this finding.

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · references/tool-intent-map.md (reported line 19)May include surrounding context.

md
| `get-profile-ua` | Get User-Agent strings for up to 10 profiles. | 批量查询最多 10 个 profile 的 UA。 | user agent, UA string, browser UA | UA,用户代理,浏览器标识 |
| `close-all-profiles` | Close all opened profiles on this device. | 关闭本机所有已打开的环境。 | close everything, stop all browsers, shutdown all profiles | 全部关闭,一键关环境,关所有浏览器 |
| `new-fingerprint` | Generate a new fingerprint for up to 10 profiles. | 为最多 10 个 profile 重新生成指纹。 | refresh fingerprint, regenerate fp, new device identity | 刷新指纹,重新指纹,换设备指纹 |
| `delete-cache-v2` | Clear selected local cache types for profiles. | 按类型清理 profile 本地缓存。 | clear cache, wipe storage, delete history cache | 清缓存,删历史,清理本地数据 |
| `share-profile` | Share profiles to another AdsPower account. | 将 profile 分享给其他 AdsPower 账号。 | share account, transfer profile, send browser to user | 分享环境,转让profile,发给同事 |
| `get-browser-active` | Get active status/details for one profile. | 查询单个 profile 的活跃/运行信息。 | is profile running, active status, browser state | 是否在线,活跃状态,运行信息 |
| `get-cloud-active` | Query cloud-side active status for many profile IDs. | 按 user_ids 批量查询云端活跃状态。 | cloud status, remote active, team multi device caveat | 云端状态,远程是否打开,多设备模式限制 |

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The metadata description contains broad trigger phrases like opening environments, profiles, proxies, or AdsPower generally, which can cause the skill to activate on loosely related user requests. Overbroad activation increases the chance that a high-privilege operational skill is invoked when the user did not clearly request profile management actions.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The skill instructs use of npx adspower-browser, which resolves and executes the latest package version unless explicitly pinned. That creates a supply-chain risk: a malicious or compromised upstream release could be pulled at runtime and executed in the user's environment.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The when-to-use section includes ambiguous activation guidance, including multilingual shorthand and broad references to browsers, profiles, fingerprint, UA, or proxy. In context, this skill can perform profile creation, deletion, cookie retrieval, and other sensitive operations, so ambiguous routing makes unintended execution more dangerous.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill documents destructive commands such as deleting profiles, tags, proxies, and cache, but does not warn about irreversible data loss or recommend confirmation. An agent using this guidance could execute high-impact state-changing actions without ensuring the user understands the consequences.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file documents a delete-browser action that deletes browser profiles, but it provides no warning that the operation may be destructive or irreversible. Under the markdown-specific warning criteria, actions affecting user data should include a clear warning about impact and recovery expectations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

Documenting direct cookie retrieval without any privacy or authorization guardrail is more security-sensitive than ordinary profile-management actions because cookies can grant authenticated session access. In this skill context, browser-profile automation increases the chance that operators handle many accounts, so exposing cookie export capability without warnings or access constraints raises account-takeover and data-exfiltration risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The delete-cache-v2 action clears local storage, IndexedDB, cookies, history, and other cached data, which directly affects user data and browsing state. Although it notes that browsers should not be open, it does not clearly warn about data removal consequences such as sign-outs or loss of local state.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The share-profile command sends profile information to an email address or phone number, which has privacy implications and may expose data outside the current account boundary. The description does not warn users about verifying recipients or the sensitivity of shared fields.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documentation exposes a destructive operation, delete-tag, without any warning that it permanently removes tags or guidance to verify the target IDs before execution. In an agent skill context, sparse docs around destructive actions can cause accidental data loss because an LLM or user may invoke deletion based only on a high-level request, without understanding consequences or confirming scope.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file begins with a Chinese title and usage instructions, which effectively forces a specific language for users consuming the skill documentation. The policy allows locale constraints only when users are given a choice or the restriction is clearly documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file documents operations that can create, update, and delete proxy records and accepts sensitive fields such as usernames and passwords. Under the markdown-specific warning criteria, it should disclose privacy or system-impact implications, but no warning is present anywhere in the description.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger map includes generic phrases such as 'open browser', 'list profiles', and 'new page' that can plausibly appear in ordinary user requests outside this skill’s intended scope. In an intent-routing system, overly broad triggers can cause accidental invocation of AdsPower actions, leading to unintended profile operations or browser automation on the local machine.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The open-browser documentation includes options to enable password filling and password saving, both of which affect stored credentials and authentication behavior. The file does not warn users that these settings may expose or persist sensitive credentials in the launched browser environment.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

Most of the file is in English, but the platform_account subfield description includes Chinese text (domain_name 和 login_user 必填,password / fakey 可选). This inconsistency can create a language accessibility issue for users who are not expecting or able to read that language, and no language choice or justification is provided.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The close-all-profiles command affects all opened browser profiles on the current device, which can disrupt active sessions or ongoing work. The description states what it does but does not warn users about the scope and impact of the action.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.