Back to skill

Security audit

axelhu-playwright-scrape

Security checks for vulnerabilities and agentic risk

Overview

This browser-scraping skill asks to expose and reuse your regular logged-in Chrome session in ways that need careful review before installation.

Install only if you are comfortable giving the skill access to a logged-in Chrome profile. Prefer an isolated temporary Chrome profile, remove the persistent google-chrome wrapper and ~/.bashrc change, avoid --no-sandbox where possible, close the debug browser after use, and do not let the skill extract or print raw cookies.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:20
Finding

Authenticated Chrome Profile Exposed Through Persistent Remote Debugging Configuration

Content
View full analysis
~/bin/google-chrome << 'EOF' #!/bin/bash exec /usr/bin/google-chrome --remote-debugging-port=9222 "$@" EOF chmod +x ~/bin/google-chrome echo 'export PATH="$HOME/bin:$PATH"' >> ~/.bashrc export PATH="$HOME/bin:$PATH" ``` From `SKILL.md:35-40`: ```bash DISPLAY=:0 google-chrome \ --remote-debugging-port=9222 \ --user-data-dir=$HOME/.config/google-chrome/Default \ --new-window \ --no-sandbox \ > /tmp/chrome-debug.log 2>&1 & ``` From `scripts/start-chrome-debug.sh:15-21`: ```bash google-chrome \ --remote-debugging-port=9222 \ --user-data-dir=$HOME/.config/google-chrome/Default \ --new-window \ --no-sandbox \ > /tmp/chrome-debug.log 2>&1 & ``` ### Technical Analysis The setup instructions create a persistent wrapper named `google-chrome` and prepend its directory to `PATH` through `.bashrc`. Consequently, future calls to `google-chrome` automatically enable the Chrome DevTools Protocol on port 9222, even when remote debugging is unrelated to the current task. The debug instance is launched against the user's normal Chrome profile, which may contain authenticated sessions, browsing data, and access to sensitive account pages. A process capable of connecting to the DevTools endpoint can remotely control tabs, execute JavaScript in page contexts, inspect network activity, and interact with authenticated websites. The browser is also started with `--no-sandbox`. This disables an important isolation boundary and increases the potential impact of a browser or renderer compromise caused by hostile web content. ### Attack Path 1. The user follows the documented setup and creates the `~/bin/google-chrome` wra ...[truncated 1233 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:103
Finding

Raw Authentication Cookie Extraction and Reuse

Content
View full analysis
c.name === 'SESSDATA')?.value; // Call the Bilibili API const resp = await fetch('https://api.bilibili.com/x/relation/followings?pn=1&ps=20&vmid=UID', { headers: { 'Cookie': 'SESSDATA=' + sessdata } }); const data = await resp.json(); ``` ### Technical Analysis The documentation directs Agent-controlled code to extract the raw `SESSDATA` authentication cookie from the browser context and manually place it in an HTTP request header. A session cookie functions as a reusable credential: possession may allow requests to be authenticated as the user until the session expires or is revoked. Extracting the credential from the browser context expands its exposure from Chrome's cookie store into JavaScript runtime state. It can consequently be disclosed through debugging output, exceptions, logs, generated code, or future modifications to the Skill. The demonstrated destination is Bilibili's API rather than an unrelated domain, and no direct exfiltration is present in the audited code. Nevertheless, direct access to the raw credential is unnecessary for ordinary page scraping and violates least-privilege design. ### Attack Path 1. The user launches GUI mode with an authenticated Chrome profile. 2. Playwright obtains access to that browser context. 3. Agent-controlled code calls `ctx.cookies()` and extracts the raw `SESSDATA` value. 4. The session credential becomes available as a normal JavaScript string. 5. A logging statement, exception handler, malicious page-driven modification, or later code change records or transmits the value. 6. A party possessing the cookie replays it in requests ...[truncated 723 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:14
Finding

Unpinned Playwright Dependency Installation

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (10)

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · SKILL.md (reported line 31)May include surrounding context.

ash cd /home/axelhu/.openclaw/workspace npm install playwright

text

## 启动 Chrome 调试实例(关键!)

### 首次设置(只需一次)

创建 Chrome wrapper,让所有 `google-chrome` 命令默认开启调试端口:

```bash
mkdir -p ~/bin
cat > ~/bin/google-chrome << 'EOF'
#!/bin/bash
exec /usr/bin/google-chrome --remote-debugging-port=9222 "$@"
EOF
chmod +x ~/bin/google-chrome
echo 'export PATH="$HOME/bin:$PATH"' >> ~/.bashrc
export PATH="$HOME/bin:$PATH"

启动 Chrome 调试实例

bash
# 必须加 DISPLAY=:0,否则 exec 会话中 Chrome 无法找到显示器
DISPLAY=:0 google-chrome \
  --remote-debugging-port=9222 \
  --user-data-dir=$HOME/.config/google-chrome/Default \
  --new-window \
  --no-sandbox \
  > /tmp/chrome-debug.log 2>&1 &

# 验证启动成功
sleep 3 && curl -s http://localhost:9222/json/version | head -c 50

注意:--user-data-dir=$HOME/.config/google-chrome/Default 使用你的默认 Chrome profile,登录状态会�

Session Persistence

Medium
Category
Rogue Agent
Confidence
84% confidence
Finding

The skill recommends altering the user's environment so all future google-chrome invocations default to enabling a remote debugging port. That creates persistent exposure of browser automation/control capabilities and can weaken the security boundary around the user's browsing session if other local processes connect to the debugging endpoint.

Content

Scanner excerpt · SKILL.md (reported line 25)May include surrounding context.

创建 Chrome wrapper,让所有 google-chrome 命令默认开启调试端口:

bash
mkdir -p ~/bin
cat > ~/bin/google-chrome << 'EOF'
#!/bin/bash
exec /usr/bin/google-chrome --remote-debugging-port=9222 "$@"

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly instructs reuse of the user's live Chrome profile and authenticated browser session, then shows how to access cookies and use them to call authenticated APIs. This exceeds ordinary page scraping and creates a capability to access account-scoped data without fresh consent, increasing the risk of unauthorized data extraction and account misuse.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
96% confidence
Finding

The example transmits an authenticated session cookie (SESSDATA) in a request to an external API, enabling access to account-linked data using the user's browser session. Even if sent to the intended service, this pattern normalizes token extraction and replay, which is dangerous because it can expose private data and facilitate unauthorized API access beyond the original scraping task.

Content

Scanner excerpt · SKILL.md (reported line 122)May include surrounding context.

md
const sessdata = cookies.find(c => c.name === 'SESSDATA')?.value;

// 调用 B站 API
const resp = await fetch('https://api.bilibili.com/x/relation/followings?pn=1&ps=20&vmid=UID', {
  headers: { 'Cookie': 'SESSDATA=' + sessdata }
});
const data = await resp.json();

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The header comments and usage/help text are presented exclusively in Chinese, and the script does not offer an alternative language or localization choice. This can violate language/locale policy where skills must not force a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script starts Chrome with --remote-debugging-port=9222 while reusing the user's default profile, which exposes an authenticated browser context to any process or party that can reach the DevTools endpoint. In combination with --no-sandbox and the use of the real profile directory, an attacker could inspect tabs, extract cookies/session data, interact with logged-in sites, or execute browser automation against sensitive accounts.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill description begins in Chinese and the rest of the document continues in that language, which can impose a specific language on users without explicit opt-in. The policy allows locale constraints only when documented and justified or when users are offered a choice.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

This code performs a network request to whatever URL is supplied via page.goto, which can transmit the user's IP, browser fingerprint, and request metadata to external systems. Although scraping is the script's purpose, the file does not include any explicit warning or disclosure comment about external network access or privacy implications.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The code collects substantial remote page content and outputs it as JSON, which could include sensitive or copyrighted material from the visited page. There is no explicit warning in comments or user-facing output describing that the tool captures and prints page text and URLs.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The natural-language content in comments and echo statements is entirely Chinese, with no option to select another language and no indication that the skill is intentionally region-specific. This can violate language/locale policy when a skill forces a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.