T09 · Insecure Skill Coding Practices
- Location
scripts/per-agent-browser.mjs:53- Finding
Chromium Sandbox Disabled by Default
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill has a coherent browser-pooling purpose, but unsafe defaults could expose or weaken logged-in browser sessions on a shared machine.
Install only in a trusted local environment and avoid using it with valuable logged-in sessions until the unsafe defaults are fixed. Prefer ephemeral or per-agent mode, avoid shared mode for sensitive accounts, set the registry to a private user-owned path, run as a non-root user, and require a pinned Playwright version with Chromium sandboxing enabled.
scripts/per-agent-browser.mjs:53Chromium Sandbox Disabled by Default
scripts/per-agent-browser.mjs:131Predictable Registry File Allows Symlink Attacks and Cross-Process Corruption
SKILL.md:37Unpinned Playwright Installation Creates Supply-Chain Risk
YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).
t id 即可。
想把具体映射存起来时,把映射文件放在
~/.config/playwright-per-agent/agents.json等 用户私有位置(不进 git / 不进 skill 包)。
| 模式 | 何时用 | 资源 |
|---|---|---|
shared | 所有 agent 共享一个 Chrome(节省资源,登录态共享) | 1 chrome |
per-agent | 每个 agent 独立 Chrome(隔离 cookies/storage/CDP 端口/进程) | N chrome |
ephemeral | 一次性,关闭后 profile 目录删除(不保留任何状态) | 临时 |
getBrowser('agent-a:scout-1', { inherit: true }) → 新 tab 在父 agent 上下文。
inherit: false → 独立 subagent 实例。
~/.openclaw/openclaw.json 的 agents.list 读所有 agent idab.registerAgent('new-id', { role: 'qa' }) 新增assets/example-config.jsonnpm install playwright
Playwright Chromium 已在本机 `~/.cache/ms-pl
Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.
## State cleanup
- **shared / per-agent**: profile persists in `~/.cache/agent-browser/<id>/`. Delete
manually to wipe state.
- **ephemeral**: profile auto-deleted on `ab.close(id)` or process exit (if
`cleanupOnExit: true`).
The documented shared mode explicitly causes multiple agents to reuse the same browser profile and authenticated session state. In a multi-agent environment this breaks isolation guarantees and can expose cookies, local storage, CSRF tokens, and active sessions from one agent to another, especially if users assume agent separation by default.
The skill describes a cross-process registry and automatic connectOverCDP attachment to active browser sessions, which means any local process that can discover the port/registry may attach to a live browser context. This can permit unauthorized observation or control of authenticated sessions, page content, cookies, and user actions if local access boundaries are weak or multiple trust levels share the same machine.
The documentation explicitly describes persistent browser profiles under a predictable cache path and only mentions manual deletion to wipe state, but it does not warn that those profiles may contain highly sensitive artifacts such as authenticated cookies, tokens, browsing history, and localStorage. In a browser-pool skill intended for agent reuse, this omission increases the likelihood that operators will retain live authenticated sessions longer than intended and expose them to other local users, processes, or later tasks.
The cross-process attach feature allows another local process to reconnect to an existing authenticated browser session via a shared registry file and CDP port, but the documentation does not warn that this effectively grants session access to any sufficiently privileged local process that can read the registry and reach the port. In the context of per-agent browser reuse, that can lead to unauthorized access to logged-in sessions, cookie theft, account actions, and cross-agent data exposure.
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
- **`.cjs`**:Playwright 1.40+ 全面 ESM 化,用 `require('playwright')` 还能工作但 import 语法更干净;
此外本 skill 不需要 CJS 兼容(没有老的 CommonJS 依赖需要桥接)。
- **`.js` + `"type": "module"`**:要在 `scripts/` 目录放一个 `package.json`,但 skill 文件结构规范
(见 `~/.openclaw/workspace-main/skills/skill-creator-plus/SKILL.md`)只允许 `SKILL.md` + `_meta.json` +
可选 `scripts/` / `references/` / `assets/`,没有 `package.json` 的位置。多一个文件就破坏了规范。
- **`.mjs`**:显式声明 ESM,无需任何配置文件。直接 import 直接用。
The file’s human-readable operational comments and usage notes are written in Chinese, which imposes a locale/language expectation on maintainers and users without any opt-in or documented rationale. Under the stated policy, forcing a specific language in natural-language content is a violation unless the file offers language choice or clearly justifies the locale constraint.
To determine port availability, the code invokes system utilities via execSync using ss or netstat. Spawning shell commands is broader than the manifest's described role of managing per-agent Playwright browser instances and is not explicitly disclosed there.
The CLI demo contradicts the 'local-only' claim by initiating a real outbound browser session to https://example.com and saving a screenshot under /tmp. Even though this is framed as a demo, it can create unexpected network egress and local artifact generation in environments that rely on the skill metadata for trust or containment decisions.
The documentation includes Chinese explanatory text in the main description while not indicating that the skill is Chinese-specific or offering an alternative language. This can violate a language/locale policy when users are not given an explicit opt-in or choice.
This manifest file states that the skill reads files under ~/.openclaw/openclaw.json and ~/.cache/agent-browser/, which are user-scoped locations that may contain configuration or browsing-related data. For markdown and manifest-style descriptions, user-facing disclosure about access to local data is expected when behavior could affect privacy.
Multiple natural-language comments and usage guidance are written only in Chinese, which imposes a specific language on users of this configuration example. The file does not offer an alternative language, opt-in, or any justification that this is a region-specific or locale-bound skill.
Detected: suspicious.dangerous_exec