Back to skill

Security audit

astrobrowse-authenticated-agentic-browser

Security checks for vulnerabilities and agentic risk

Overview

AstroBrowse is a coherent authenticated-browser automation skill, but it can make real changes inside logged-in accounts and persist session artifacts, so users should review it carefully before enabling it.

Install only if you intend to let an agent operate selected logged-in websites through AgentPMT. Connect the minimum necessary accounts, keep browsing policy restrictive, require the agent to ask before posting, submitting, updating records, downloading exports, or recording sessions, and prefer pinned or OpenClaw install routes for supporting skills.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (15)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill advertises the ability to operate logged-in websites, update records, submit forms, and perform other consequential actions, but it does not prominently require explicit user confirmation before high-impact changes. In an authenticated browser context, missing consent and warning language raises the risk of accidental transactions, destructive edits, or unauthorized disclosure from within real user accounts.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The activation keywords include broad task-oriented phrases such as posting content, updating records, and filling forms, which can cause the skill to be selected in contexts that do not specifically require AstroBrowse. Over-broad invocation is dangerous because this skill enables high-impact actions in authenticated sessions, increasing the chance of unintended account changes or data access.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The use cases list includes posting, updating CRMs/ERPs, submitting forms, downloading files, and extracting data behind login, yet it lacks a corresponding caution about business impact, privacy exposure, or irreversible actions. Because the skill operates on live authenticated sessions, omission of a strong warning materially increases the chance of unsafe or unintended use.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
86% confidence
Finding

The skill instructs users to install supporting components via npx skills without pinning an exact package version or immutable source. That creates a supply-chain risk: a later package update, dependency compromise, or namespace takeover could cause users to fetch and execute unexpected code during installation.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
86% confidence
Finding

This installation command uses an unpinned npx skills invocation, which can resolve to whatever package version is current at execution time. In a security-sensitive ecosystem that grants browser automation over authenticated sessions, executing mutable installer code raises meaningful supply-chain exposure.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
86% confidence
Finding

The skill references npx skills without version pinning, allowing silent drift to newer or compromised package contents. Because this skill enables access to authenticated browsing workflows, compromise of the install path could lead to broad downstream account or data exposure.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
86% confidence
Finding

An unpinned npx skills install command introduces avoidable package-resolution and dependency-substitution risk. Users following these instructions may unknowingly execute changed code from the registry, which is especially concerning for tooling tied to remote browser control and account access.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
86% confidence
Finding

This is another floating npx skills reference that can pull different code over time, making installations non-reproducible and vulnerable to supply-chain compromise. The surrounding context increases risk because the installed tooling participates in authenticated browser sessions and remote actions.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
86% confidence
Finding

The command uses npx skills without fixing the version, so users may execute whatever package version is currently served. That is a classic documentation-driven supply-chain weakness and is more consequential here due to the privileged browser-automation capabilities described by the skill.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
86% confidence
Finding

This unpinned installer invocation leaves consumers exposed to package updates or compromise outside the skill author's control. Given that the overall tool can act inside logged-in user accounts, compromise at install time could have significant follow-on effects.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 236)May include surrounding context.

md
- What AgentPMT is: ../what-is-agentpmt (ClawHub: `what-is-agentpmt`, page: https://clawhub.ai/agentpmt/what-is-agentpmt; skills.sh: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`)
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/astrobrowse-authenticated-agentic-browser
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 237)May include surrounding context.

md
- What AgentPMT is: ../what-is-agentpmt (ClawHub: `what-is-agentpmt`, page: https://clawhub.ai/agentpmt/what-is-agentpmt; skills.sh: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`)
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/astrobrowse-authenticated-agentic-browser
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The screenshot action saves a PNG of the active authenticated browser page to File Manager, but the schema lacks a clear warning that screenshots can preserve sensitive page contents, including personal data, financial information, internal dashboards, or other protected material. Because this tool operates on real logged-in sessions, saving screenshots creates a durable artifact that may outlive the session and broaden exposure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill exposes screen recording of an authenticated browser session and states that the MP4 is saved to File Manager, but the schema text does not clearly warn that recordings may capture sensitive on-screen data such as inbox contents, account data, personal information, or secrets shown during navigation or human takeover. In an authenticated remote-browser context, this increases the risk of over-collection and unintended retention of sensitive material beyond the live session.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The download_file action persists browser-downloaded files into File Manager, but the schema does not clearly emphasize that downloaded content may contain sensitive or regulated data and will be retained outside the transient browser session. In an authenticated SaaS/portal workflow, this can lead to inadvertent storage of confidential exports or reports.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.