Back to skill

Security audit

Playwright Per-Agent Browser Pool

Security checks for vulnerabilities and agentic risk

Overview

The skill has a coherent browser-pooling purpose, but unsafe defaults could expose or weaken logged-in browser sessions on a shared machine.

Install only in a trusted local environment and avoid using it with valuable logged-in sessions until the unsafe defaults are fixed. Prefer ephemeral or per-agent mode, avoid shared mode for sensitive accounts, set the registry to a private user-owned path, run as a non-root user, and require a pinned Playwright version with Chromium sandboxing enabled.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/per-agent-browser.mjs:53
Finding

Chromium Sandbox Disabled by Default

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/per-agent-browser.mjs:131
Finding

Predictable Registry File Allows Symlink Attacks and Cross-Process Corruption

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:37
Finding

Unpinned Playwright Installation Creates Supply-Chain Risk

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (13)

YARA rule 'info_stealer': Information stealer patterns (credential harvesting, browser data theft) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · SKILL.md (reported line 23)May include surrounding context.

t id 即可。

想把具体映射存起来时,把映射文件放在 ~/.config/playwright-per-agent/agents.json 等 用户私有位置(不进 git / 不进 skill 包)。

三种 Profile 模式

模式何时用资源
shared所有 agent 共享一个 Chrome(节省资源,登录态共享)1 chrome
per-agent每个 agent 独立 Chrome(隔离 cookies/storage/CDP 端口/进程)N chrome
ephemeral一次性,关闭后 profile 目录删除(不保留任何状态)临时

Subagent 支持

getBrowser('agent-a:scout-1', { inherit: true }) → 新 tab 在父 agent 上下文。 inherit: false → 独立 subagent 实例。

自动扩展

  • 启动时从 ~/.openclaw/openclaw.json 的 agents.list 读所有 agent id
  • 运行时 ab.registerAgent('new-id', { role: 'qa' }) 新增
  • 详见 assets/example-config.json

安装

bash
npm install playwright

Playwright Chromium 已在本机 `~/.cache/ms-pl

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · references/profile-strategies.md (reported line 68)May include surrounding context.

md
## State cleanup

- **shared / per-agent**: profile persists in `~/.cache/agent-browser/<id>/`. Delete
  manually to wipe state.
- **ephemeral**: profile auto-deleted on `ab.close(id)` or process exit (if
  `cleanupOnExit: true`).

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documented shared mode explicitly causes multiple agents to reuse the same browser profile and authenticated session state. In a multi-agent environment this breaks isolation guarantees and can expose cookies, local storage, CSRF tokens, and active sessions from one agent to another, especially if users assume agent separation by default.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill describes a cross-process registry and automatic connectOverCDP attachment to active browser sessions, which means any local process that can discover the port/registry may attach to a live browser context. This can permit unauthorized observation or control of authenticated sessions, page content, cookies, and user actions if local access boundaries are weak or multiple trust levels share the same machine.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documentation explicitly describes persistent browser profiles under a predictable cache path and only mentions manual deletion to wipe state, but it does not warn that those profiles may contain highly sensitive artifacts such as authenticated cookies, tokens, browsing history, and localStorage. In a browser-pool skill intended for agent reuse, this omission increases the likelihood that operators will retain live authenticated sessions longer than intended and expose them to other local users, processes, or later tasks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The cross-process attach feature allows another local process to reconnect to an existing authenticated browser session via a shared registry file and CDP port, but the documentation does not warn that this effectively grants session access to any sufficiently privileged local process that can read the registry and reach the port. In the context of per-agent browser reuse, that can lead to unauthorized access to logged-in sessions, cookie theft, account actions, and cross-agent data exposure.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · references/why-mjs.md (reported line 23)May include surrounding context.

md
- **`.cjs`**:Playwright 1.40+ 全面 ESM 化,用 `require('playwright')` 还能工作但 import 语法更干净;
  此外本 skill 不需要 CJS 兼容(没有老的 CommonJS 依赖需要桥接)。
- **`.js` + `"type": "module"`**:要在 `scripts/` 目录放一个 `package.json`,但 skill 文件结构规范
  (见 `~/.openclaw/workspace-main/skills/skill-creator-plus/SKILL.md`)只允许 `SKILL.md` + `_meta.json` +
  可选 `scripts/` / `references/` / `assets/`,没有 `package.json` 的位置。多一个文件就破坏了规范。
- **`.mjs`**:显式声明 ESM,无需任何配置文件。直接 import 直接用。

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file’s human-readable operational comments and usage notes are written in Chinese, which imposes a locale/language expectation on maintainers and users without any opt-in or documented rationale. Under the stated policy, forcing a specific language in natural-language content is a violation unless the file offers language choice or clearly justifies the locale constraint.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

To determine port availability, the code invokes system utilities via execSync using ss or netstat. Spawning shell commands is broader than the manifest's described role of managing per-agent Playwright browser instances and is not explicitly disclosed there.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The CLI demo contradicts the 'local-only' claim by initiating a real outbound browser session to https://example.com and saving a screenshot under /tmp. Even though this is framed as a demo, it can create unexpected network egress and local artifact generation in environments that rely on the skill metadata for trust or containment decisions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The documentation includes Chinese explanatory text in the main description while not indicating that the skill is Chinese-specific or offering an alternative language. This can violate a language/locale policy when users are not given an explicit opt-in or choice.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

This manifest file states that the skill reads files under ~/.openclaw/openclaw.json and ~/.cache/agent-browser/, which are user-scoped locations that may contain configuration or browsing-related data. For markdown and manifest-style descriptions, user-facing disclosure about access to local data is expected when behavior could affect privacy.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

Multiple natural-language comments and usage guidance are written only in Chinese, which imposes a specific language on users of this configuration example. The file does not offer an alternative language, opt-in, or any justification that this is a region-specific or locale-bound skill.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/per-agent-browser.mjs:103