T05 · Unauthorized Access and Privilege Escalation
- Location
_meta.json:7- Finding
Misleading manifest permits autonomous invocation of undisclosed high-risk browser-control capabilities
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill combines ordinary web search with high-risk local browser-control features, while its registry metadata understates those capabilities.
Do not install this as a normal scraper. Only evaluate it in a disposable VM or container with no personal browser profile, no authenticated sessions, and Chrome DevTools exposed only to a dedicated test browser. Before publication or trusted use, align the manifests, disable autonomous invocation consistently, remove or strongly broker CDP takeover paths, fix the wrapper path validation, keep Chromium sandboxing enabled, and pin dependencies.
_meta.json:7Misleading manifest permits autonomous invocation of undisclosed high-risk browser-control capabilities
scripts/nuclear_option.py:8Direct browser takeover is protected only by a forgeable environment variable
scripts/sota_core.py:33Protected launcher allows path traversal and arbitrary Python-file execution
scripts/python_relay.py:58Chrome DevTools relay can be started and used without the documented authorization gate
scripts/sota_security.py:5Lockfile authorization can be forged and is not issued by the documented wrapper
scripts/drission_util.py:20Chromium is launched with its process sandbox disabled
requirements.txt:1Unbounded dependency constraints prevent reproducible, reviewed installations
The reported behavior includes targeting a specific third-party site, scraping/extracting content, and writing evidence files, none of which are declared in the description. In context, undeclared external collection plus local evidence storage is materially more dangerous than the stated toolkit framing because it can hide surveillance, policy violations, or unauthorized data harvesting.
The reported behavior includes targeting a specific third-party site, scraping/extracting content, and writing evidence files, none of which are declared in the description. In context, undeclared external collection plus local evidence storage is materially more dangerous than the stated toolkit framing because it can hide surveillance, policy violations, or unauthorized data harvesting.
The reported behavior includes targeting a specific third-party site, scraping/extracting content, and writing evidence files, none of which are declared in the description. In context, undeclared external collection plus local evidence storage is materially more dangerous than the stated toolkit framing because it can hide surveillance, policy violations, or unauthorized data harvesting.
The reported behavior includes targeting a specific third-party site, scraping/extracting content, and writing evidence files, none of which are declared in the description. In context, undeclared external collection plus local evidence storage is materially more dangerous than the stated toolkit framing because it can hide surveillance, policy violations, or unauthorized data harvesting.
The reported behavior includes targeting a specific third-party site, scraping/extracting content, and writing evidence files, none of which are declared in the description. In context, undeclared external collection plus local evidence storage is materially more dangerous than the stated toolkit framing because it can hide surveillance, policy violations, or unauthorized data harvesting.
The reported behavior includes targeting a specific third-party site, scraping/extracting content, and writing evidence files, none of which are declared in the description. In context, undeclared external collection plus local evidence storage is materially more dangerous than the stated toolkit framing because it can hide surveillance, policy violations, or unauthorized data harvesting.
The reported behavior includes targeting a specific third-party site, scraping/extracting content, and writing evidence files, none of which are declared in the description. In context, undeclared external collection plus local evidence storage is materially more dangerous than the stated toolkit framing because it can hide surveillance, policy violations, or unauthorized data harvesting.
The reported behavior includes targeting a specific third-party site, scraping/extracting content, and writing evidence files, none of which are declared in the description. In context, undeclared external collection plus local evidence storage is materially more dangerous than the stated toolkit framing because it can hide surveillance, policy violations, or unauthorized data harvesting.
The reported behavior includes targeting a specific third-party site, scraping/extracting content, and writing evidence files, none of which are declared in the description. In context, undeclared external collection plus local evidence storage is materially more dangerous than the stated toolkit framing because it can hide surveillance, policy violations, or unauthorized data harvesting.
The reported behavior includes targeting a specific third-party site, scraping/extracting content, and writing evidence files, none of which are declared in the description. In context, undeclared external collection plus local evidence storage is materially more dangerous than the stated toolkit framing because it can hide surveillance, policy violations, or unauthorized data harvesting.
The reported behavior includes targeting a specific third-party site, scraping/extracting content, and writing evidence files, none of which are declared in the description. In context, undeclared external collection plus local evidence storage is materially more dangerous than the stated toolkit framing because it can hide surveillance, policy violations, or unauthorized data harvesting.
The reported behavior includes targeting a specific third-party site, scraping/extracting content, and writing evidence files, none of which are declared in the description. In context, undeclared external collection plus local evidence storage is materially more dangerous than the stated toolkit framing because it can hide surveillance, policy violations, or unauthorized data harvesting.
The reported behavior includes targeting a specific third-party site, scraping/extracting content, and writing evidence files, none of which are declared in the description. In context, undeclared external collection plus local evidence storage is materially more dangerous than the stated toolkit framing because it can hide surveillance, policy violations, or unauthorized data harvesting.
The metadata presents the package as only basic search and aggregation, while the requirements indicate substantially broader automation support through Chrome and DrissionPage. Misrepresenting capability scope is a security issue because downstream reviewers may approve or invoke the skill under false assumptions, enabling unexpected automated browsing, scripted interaction, or collection behavior.
The manifest claims the skill is a minimal scraper with no high-risk capabilities, but the declared dependencies support full browser automation and protocol-level request manipulation. This kind of capability mismatch is dangerous because it can conceal a much broader operational surface from reviewers and users, undermining informed consent and making abuse or policy evasion easier.
Copying the full parent environment into a child process is not a clean environment and can unintentionally propagate sensitive variables such as tokens, proxy settings, debugging hooks, or dangerous interpreter controls. In this skill context, which explicitly launches additional Python scripts, inherited environment variables can influence child behavior, leak secrets, or weaken the claimed security boundary.
script_path = os.path.join(base_dir, script_name)
# 1. Clean Environment
clean_env = os.environ.copy()
clean_env['SOTA_INTERNAL_AUTH'] = 'TRUE'
# 2. Atomic Execution
The skill advertises and likely uses powerful capabilities (environment access, filesystem read/write, network, and shell) without declaring an explicit tool scope such as permissions or allowed-tools. This weakens least-privilege boundaries and makes it easier for a consumer to invoke a skill with broader access than expected, increasing the blast radius if the skill is misused or compromised.
Dependencies such as DrissionPage, google-chrome-stable, and curl_cffi are not well-justified by a description limited to basic search and aggregation. Unnecessary high-capability dependencies expand the attack surface, allow behavior beyond declared scope, and make it harder to distinguish legitimate scraping from stealthier or more invasive automation.
The script exposes an explicit Chrome DevTools Protocol takeover path by discovering a local debugger endpoint and connecting directly to its WebSocket debugger URL. Even with a local Unix-domain-socket gate, this is a high-risk capability because it enables control of an existing browser session, which can expose authenticated sessions, page contents, cookies, and user actions far beyond ordinary automation semantics.
This code implements deliberate browser-session takeover by querying /json/version and attaching to the returned webSocketDebuggerUrl, which is a standard path for assuming control over a live browser context. In skill context, this is more dangerous because the toolkit advertises stealthy web-intelligence features and local socket relaying, making unauthorized surveillance or session hijacking a plausible misuse case rather than a purely administrative automation feature.
The manifest claims features such as 'Protocol Phantom (TLS/JA4), Local Socket Relaying, and Hardened physical gating,' but this file only issues two straightforward HTTP GET requests to arXiv and DuckDuckGo, parses HTML, and writes a JSON report. This is a semantic mismatch between the advertised capability and the actual behavior implemented here.
The function sends the user-supplied query to arXiv over the network without any explicit disclosure, consent flow, or privacy notice. If users provide sensitive research topics, identifiers, or proprietary terms, that data is exposed to a third party and may be logged externally.
The second request sends the same user query to DuckDuckGo without clear disclosure that the input is being shared with another external provider. In a web-intelligence skill context, users may reasonably submit sensitive investigative terms, making undisclosed third-party transmission more concerning.
This code directly attaches to a local Chrome DevTools Protocol endpoint and instantiates a low-level browser driver, bypassing higher-level controls and any normal skill boundary assumptions. Even with an environment-variable gate, this enables arbitrary browser automation against an already-running browser context, which can expose cookies, authenticated sessions, page contents, and privileged browser actions if invoked.
Attaching to a local debugging socket is an invasive capability because the DevTools socket provides broad control over the browser, including navigation and script evaluation. In the context of a web intelligence/automation toolkit, this is more dangerous because it targets an existing local browser on 127.0.0.1, potentially inheriting user state and authenticated data rather than operating in an isolated session.
No suspicious patterns detected.