Back to skill

Security audit

Browser Storage

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only browser storage guidance skill with coherent, disclosed behavior and no executable code or hidden authority.

This skill is reasonable to install for frontend work involving localStorage, sessionStorage, IndexedDB, cookies, offline caches, and sensitive-data handling. Users should still review generated storage code carefully, especially authentication/session handling, and prefer server-set httpOnly cookies for tokens as the skill itself recommends.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 10)May include surrounding context.

md
- ID: `fec-browser-storage`
- Category: `implementation-capability`
- Version: `2.9.0`
- Source: `skills/fec-browser-storage/SKILL.md`

## Description

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The README describes activation as 'Use when choosing, implementing, or reviewing browser storage' followed by a long list of related topics, but it does not define clear boundaries for when this skill should or should not be invoked. Without explicit constraints or negative examples, the trigger scope is broad enough to cause unintended matches across many frontend or persistence-related requests.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill trigger text is very broad and can match routine discussions about browser storage, client persistence, cookies, or offline data. Over-broad activation can cause the agent to invoke this skill in unrelated contexts, increasing the chance of inappropriate guidance being surfaced and expanding the attack surface for prompt-routing or context hijacking.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest description says 'Use when choosing, implementing, or reviewing browser storage' and then lists a wide range of related topics and triggers, but it does not define specific invocation phrases, boundaries, or negative examples. In a manifest file, this breadth can make activation ambiguous for ordinary discussions about storage, cookies, or offline data.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The description says to use the skill when 'choosing, implementing, or reviewing browser storage' and lists very broad concepts like 'cleanup strategy' and 'client persistence.' While domain-related, it does not define explicit trigger phrases, exclusions, or boundaries for when this skill should not activate, which can cause over-invocation in general frontend conversations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The natural-language description explicitly calls out 'Chinese triggers include browser storage, client persistence,' which introduces a language-specific activation behavior. The file does not indicate that users can choose other languages or that the locale restriction is intentional and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The description explicitly states 'Chinese triggers include browser storage, client persistence,' which introduces a language-specific activation policy. The file does not indicate that multilingual triggering is optional, user-selected, or justified by a region-specific purpose.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.