Agent Browser Skill

Security checks across malware telemetry and agentic risk

Overview

The skill appears to provide browser automation guidance, and the main risk is ordinary privacy exposure when users choose to interact with external websites.

Install only if you intend the agent to operate websites on your behalf. Avoid submitting secrets, tokens, regulated data, or sensitive personal information unless you trust the target site and have authorization, and review actions before form submission or data extraction.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
86% confidence
Finding
The skill provides concrete examples for form filling and content extraction against third-party sites but does not warn that prompts, form fields, page contents, cookies, and other user-supplied data may be transmitted to external domains. In an agent setting, this omission can lead users to automate actions with sensitive data under the assumption the skill is locally safe, creating privacy, compliance, and unintended data disclosure risks.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal