Back to skill

Security audit

SmoothBrowser

Security checks across malware telemetry and agentic risk

Overview

SmoothBrowser appears legitimate, but it gives an agent broad third-party browser control over logins, files, JavaScript, and saved sessions without enough explicit approval boundaries.

Install only if you are comfortable letting Smooth, a third-party browser automation provider, operate websites on your behalf. Use anonymous or read-only sessions when possible, restrict allowed URLs, avoid uploading sensitive files unless necessary, and require explicit approval before reusing logged-in profiles, submitting forms, posting content, purchasing, downloading private data, or changing account settings.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger description is very broad ('any task on the web', 'any browser interaction request') and is likely to activate for many common requests without sufficient scoping. In an agent environment, over-broad invocation increases the chance the skill is selected for sensitive actions such as logging in, form filling, scraping, or data transfer when a safer or more specialized path should be used.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill instructs agents to upload local files to an external Smooth service but does not warn that file contents leave the local environment and may contain sensitive data. This creates a real risk of inadvertent exfiltration of confidential documents, credentials, invoices, contracts, screenshots, or regulated data through normal skill usage.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill promotes persistent profiles for cookies, login sessions, and browser state without clearly warning that this retains sensitive authentication material and browsing artifacts across sessions. In shared or semi-trusted agent environments, persisted sessions can enable unintended reuse of authenticated state, cross-task access, or account actions without fresh user awareness.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.