Back to skill

Security audit

live-web-page-browser

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed remote web-browsing integration, with some privacy and session-management cautions users should understand before use.

Install only if you are comfortable using AgentPMT-hosted infrastructure for live web access. Do not submit private internal URLs, URLs containing tokens, authenticated pages, personal data, or confidential business content unless you have approval, and be careful with account-level browser session and crawl controls because they may affect other AgentPMT browser runs.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Description-Behavior Mismatch

Medium
Confidence
88% confidence
Finding
The schema includes browser-session management actions such as listing and killing active sessions, which expands the tool's effective authority beyond simple page fetching and browsing described in the metadata. Undocumented session-control capabilities can be misused by an agent to enumerate account activity or disrupt other browser runs, increasing the risk of lateral interference and confusing users about the true privilege scope of the skill.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The activation keywords are broad enough to match many ordinary browsing, research, fact-checking, and monitoring requests, which can cause the skill to be invoked in situations where the user did not explicitly intend to send URLs or retrieved content to this remote service. Because this tool performs live web fetches and third-party processing, overbroad triggering increases the risk of unintended external transmission and unexpected browsing actions.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill describes live webpage fetching and content extraction but does not clearly warn that requested URLs, page contents, screenshots, and extraction prompts are transmitted to a third-party remote service. This can lead users or agents to disclose sensitive internal URLs, tokens in query strings, or confidential page contents without informed consent.

Missing User Warnings

Medium
Confidence
82% confidence
Finding
The skill exposes multiple live web fetch, render, screenshot, PDF, JSON extraction, and crawl operations without visible warnings about external network access, privacy implications, or handling of sensitive/internal URLs. In practice, an agent could be induced to contact attacker-controlled endpoints, crawl unintended sites, or process sensitive content without adequate user awareness, creating SSRF-like privacy and data exposure risks at the product boundary.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.