Back to skill

Security audit

Luke Agent Browser Clawdbot

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward browser automation guide, with expected but sensitive browser-session features that users should handle carefully.

Before installing, treat saved auth state, cookies, and storage values as secrets: do not commit or share them, prefer test accounts, and avoid printing sensitive values in logs. For installation, consider using a sandbox or project-local pinned version of agent-browser instead of an unpinned global install, especially on systems with sensitive data.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:197
Finding

Unpinned Global Dependency Installation and Unverified Secondary Downloads

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 197-199
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Medium

Vulnerable Code:

bash
npm install -g agent-browser
agent-browser install                     # Download Chromium
agent-browser install --with-deps         # Linux: + system deps

Technical Analysis

The installation instructions globally install agent-browser without pinning an exact package version or verifying package integrity. Consequently, the code installed and executed can change after this Skill has been reviewed, even though the Skill package itself remains unchanged.

The newly installed CLI is then trusted to download Chromium. The --with-deps option may also install operating-system dependencies, potentially under elevated privileges. No version constraints, lockfile, cryptographic checksums, trusted artifact locations, or post-download verification procedures are provided.

This creates a third-party supply-chain exposure. A compromised maintainer account, malicious package release, registry compromise, or unexpected upstream change could cause installation-time lifecycle scripts or CLI commands to execute attacker-controlled code.

Attack Path

  1. An attacker compromises the upstream npm package, its publisher account, release pipeline, or a dependency included in a future release.
  2. The attacker publishes a modified version under the expected package name.
  3. A user follows SKILL.md and runs npm install -g agent-browser without an exact version constraint.
  4. npm resolves the current package release and executes any applicable installation lifecycle code.
  5. The user runs agent-browser install or agent-browser install --with-deps.
  6. The compromised CLI downloads or installs additional attacker-controlled components.
  7. The malicious code executes with the privileges of the invoking user or, where elevated system dependency instal ...[truncated 632 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin agent-browser to an exact reviewed version rather than relying on the latest registry release.
  2. Prefer a project-local installation governed by a committed lockfile instead of a global installation.
  3. Use npm integrity metadata and a reproducible installation method such as npm ci where applicable.
  4. Document the expected official registry, package publisher, repository, and release provenance.
  5. Verify downloaded Chromium artifacts using vendor-provided cryptographic checksums or signatures.
  6. Pin the Chromium revision and system dependency versions where supported.
  7. Review package lifecycle scripts and transitive dependencies before approving upgrades.
  8. Run installation in a sandbox, container, or other least-privilege environment.
  9. Avoid --with-deps unless it is necessary. Clearly disclose any administrative privileges it requires and provide a reviewed list of system packages that it installs.
  10. Establish an explicit dependency update and security-review process so upstream changes are not adopted automatically.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill explicitly documents saving and loading browser auth state, which typically includes cookies and local/session storage, but provides no warning that these artifacts may contain active session tokens or other sensitive credentials. In an agent context, this can normalize insecure handling of reusable authentication material and lead to account takeover if files are stored, shared, or reused across users or environments.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill advertises commands to read and modify cookies and browser storage without any caution about privacy, account impact, or the sensitivity of stored values. In a browser automation skill, this increases the risk that an agent or user will inspect, exfiltrate, overwrite, or replay session data in ways that compromise accounts or violate data-handling expectations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.