Back to skill

Security audit

astrobrowse-authenticated-agentic-browser

Security checks across malware telemetry and agentic risk

Overview

The skill is a coherent authenticated browser integration, but it can take real actions in logged-in accounts and persist session artifacts without a clear per-action consent model.

Install only if you are comfortable letting an agent operate selected logged-in web accounts. Use it for narrowly scoped tasks, confirm before any public post, record change, submission, download, screenshot, or recording, and avoid using it on accounts with sensitive data unless the File Manager retention and access controls fit your needs.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The activation keywords include broad generic tasks such as posting content, pulling reports, updating records, and filling forms, which can cause the skill to be invoked in situations far beyond a narrowly scoped authenticated browser use case. Because this skill can operate logged-in sessions and perform consequential actions on third-party sites, overbroad triggering increases the chance of unintended account actions or data handling without sufficiently specific user intent.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill enables high-impact authenticated actions such as posting, modifying records, submitting forms, and downloading files, but it does not prominently warn that these actions can alter user accounts, trigger external side effects, or expose sensitive business data. In an agentic context, the absence of an explicit caution/confirmation model increases the risk of accidental destructive or privacy-impacting operations.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The schema documents starting and stopping screen recording but does not clearly warn that the recording may capture sensitive on-screen data from authenticated sessions, including personal data, financial information, internal business records, or MFA prompts. In the context of an authenticated remote browser skill, saved recordings materially increase privacy and data-retention risk because captured content is persisted to the File Manager and may be reviewed later outside the live session.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The screenshot action states that a PNG will be captured and saved to the File Manager, but it does not clearly warn that the image can contain sensitive authenticated page content. Because this skill operates real logged-in browser sessions, screenshots can expose account data, PII, financial records, support tickets, CRM contents, and other confidential material beyond the immediate task.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The download_file action explains that browser downloads can be persisted into the File Manager, but it does not explicitly warn that downloaded materials may contain sensitive or regulated data and will be stored outside the browser session. In an authenticated browser tool, this increases the risk of unintended retention and broader access to confidential documents obtained from SaaS portals, CRMs, ERPs, or other private systems.

VirusTotal

52/52 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.