Back to skill

Security audit

Browser Automation V2

Security checks for vulnerabilities and agentic risk

Overview

This browser automation skill matches its stated purpose, but it uses unsafe shell execution with user-supplied URLs, search terms, form data, and profile values, creating a real local command-execution risk.

Install only after the publisher replaces shell-based exec calls with argument-based execution, validates URLs and browser refs, removes logging of form values, and documents where screenshots/PDFs are saved. Avoid using this skill with secrets, authenticated browser sessions, or untrusted URLs/search/form inputs in its current form.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (5)

T09 · Insecure Skill Coding Practices

Error
Location
browser-manager.v2.js:61
Finding

Shell Command Injection in Browser Command Execution

Content
View full analysis
{ const attempt = (n) => { this.logger.debug(`Exec: ${cmd} (attempt ${n + 1})`); exec(cmd, { timeout }, async (err, stdout, stderr) => { if (err) { this.logger.warn(`Command failed: ${stderr || err.message}`); if (n < retries && /ENETUNREACH|ECONNREFUSED|ETIMEDOUT/.test(stderr || '')) { const backoff = 1000 * Math.pow(2, n); this.logger.info(`Retrying in ${backoff}ms...`); await new Promise(r => setTimeout(r, backoff)); return attempt(n + 1); } reject({ err, stdout, stderr, attempt: n + 1 }); } else { resolve({ stdout, stderr }); } }); }; attempt(0); }); } ``` Representative vulnerable call sites include: ```js await this.runCommand(`openclaw browser --browser-profile ${this.profile} open "${url}"`); await this.runCommand(`openclaw browser --browser-profile ${this.profile} type ${ref} "${text}"`); await this.runCommand(`openclaw browser --browser-profile ${this.profile} press ${key}`); ``` ### Technical Analysis `child_process.exec()` runs its input through a system shell. The command strings are assembled through template interpolation using values that can originate from command-line arguments or environment variables, including: - URLs supplied to `fetch-summary.js`, `multi-pages.js`, or benchmark mode - Form values supplied to `fill-form.js` - Search terms supplied to `search-google.js` - `BROWSER_PROFILE` - Othe ...[truncated 1891 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
fetch-summary.js:23
Finding

Direct Shell Command Injection in Static Web Fetch

Content
View full analysis
{ exec(`openclaw web_fetch "${url}" --max-chars 10000`, { timeout: 15000 }, (err, stdout, stderr) => { if (err) reject(err); else resolve(stdout); }); }); console.log('✅ 成功获取网页内容(静态)'); const content = result.substring(0, 2000); ``` The URL comes directly from the command line: ```js const url = process.argv[2]; ``` ### Technical Analysis The command-line URL is directly embedded in a command passed to `child_process.exec()`. Because `exec()` invokes a shell, shell substitutions inside the quoted URL are evaluated. No URL parsing, scheme restriction, shell escaping, or argument separation occurs. This is independent of the command-injection issue in `BrowserManager`: the vulnerable static-fetch command runs before the script switches to browser mode. ### Attack Path 1. An attacker convinces a user or agent to invoke `fetch-summary.js` with a crafted URL. 2. The URL includes shell syntax that remains active inside double quotes, such as command substitution. 3. The script interpolates the URL into `openclaw web_fetch "${url}" --max-chars 10000`. 4. `exec()` invokes the system shell. 5. The shell evaluates the injected command using the Skill process's account. 6. The subsequent `openclaw web_fetch` operation may succeed or fail; exploitation does not depend on a successful network fetch. ### Impact Assessment An attacker can execute arbitrary commands with the permissions of the Skill process. This can expose readable local data, alter user files, access OpenClaw or browser state, and initiate arbitrary outbound connections. The vulnerability does not inherently grant privileges beyond those ...[truncated 32 chars]
Remediation
View remediation
{ if (err) reject(err); else resolve(stdout); } ); ``` Before execution: 1. Parse the input with `new URL(url)`. 2. Permit only required schemes, preferably `https:` and optionally `http:`. 3. Reject embedded credentials unless explicitly required. 4. Consider controls against access to loopback, link-local, private-network, and cloud metadata destinations if untrusted users can select URLs. 5. Set output-size and execution-time limits. 6. Do not attempt to solve this solely by adding shell escaping; avoiding the shell is the safer design. ]]>

T09 · Insecure Skill Coding Practices

Error
Location
fill-form.js:27
Finding

Sensitive Form Data Exposed Through Process Arguments and Logs

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
browser-manager.v2.js:23
Finding

Predictable and Non-Atomic Temporary Lock File Handling

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
browser-manager.v2.js:28
Finding

Concurrency Lock Deletes Valid Active Locks

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (14)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 16)May include surrounding context.

md
- `browser-manager.v2.js` - Core manager class

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 19)May include surrounding context.

md
- `multi-pages.js` - Batch process multiple URLs

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
88% confidence
Finding

With no manifest available, there is no declared purpose that would justify exposing a general subprocess-execution capability. The core implementation wraps child_process.exec and then builds shell command strings from method inputs, giving the skill OS-command execution power rather than a narrowly constrained browser API.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill advertises browser actions that can modify external systems or capture sensitive information, including form auto-fill, screenshots, and PDF generation, but provides no user-facing warning about those side effects. In an agent setting, this increases the chance of unintended submissions, data leakage, or collection of sensitive page content because users may invoke the skill without understanding its write/capture behavior.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
76% confidence
Finding

The code changes behavior based on process.env.DEBUG and later consumes BROWSER_PROFILE, BROWSER_TIMEOUT, and BROWSER_RETRIES from environment variables. For an unknown-purpose skill, reading environment configuration is an additional capability not inherently required by the browser-management methods themselves and is not justified by any manifest scope.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The code constructs shell commands with untrusted input and executes them via exec, which invokes a shell. At line 129, the ref parameter is inserted unquoted into the command string, so an attacker controlling ref could inject shell metacharacters and execute arbitrary OS commands in the skill's runtime context.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The doc comment describes the tool as '网页内容获取与摘要自动化' and the usage suggests a fetch-and-summary workflow. In practice, the code retrieves page content, prints a preview, and merely tells the user they can use an agent to summarize it later, which contradicts the stated behavior rather than just omitting an implementation detail.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This file contains natural-language strings such as the header description and the error/help text only in Chinese. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is explicitly justified, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The file’s natural-language interface and user-facing messages are entirely in Chinese, including the title, usage guidance, and error output. This imposes a specific language/locale on users without any opt-in or documented justification, which matches the language-policy violation criteria.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This code performs file-generating operations by taking a screenshot and exporting a PDF, which can persist potentially sensitive search results or browser content on disk. While there is a console log after the screenshot, there is no prior warning, confirmation, or comment/docstring disclosing that local files will be created.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The primary descriptive text for the skill is written only in Chinese, which can constitute a language/locale policy issue when no user choice or opt-in is offered. There is no accompanying indication that the skill is intentionally region-specific or that alternative language support is available.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The pdf method triggers a browser command that saves a PDF, which affects user data/storage by writing a file. The code logs after completion but does not disclose beforehand where output is written or warn that a file will be created.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file contains user-facing description and runtime messages entirely in Chinese, including usage and error output. Under the policy, forcing a specific language without user opt-in is a natural-language locale violation unless the constraint is explicitly documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The natural-language description and usage instructions force a specific language/locale without indicating that the user can choose another language. Under the stated policy, locale-specific behavior should either be optional or clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
browser-manager.v2.js:66

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
fetch-summary.js:27