Back to skill

Security audit

Browser Act Skill Forge

Security checks across malware telemetry and agentic risk

Overview

This skill is a powerful browser automation skill generator with disclosed useful behavior, but it also under-describes write actions and includes rate-limit evasion guidance.

Review this carefully before installing. Use it only for sites and accounts where you are authorized to automate, avoid state-changing tasks unless you can supervise every action, and do not use the stealth session or fingerprint guidance to bypass rate limits or site controls.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (10)

Description-Behavior Mismatch

Medium
Confidence
97% confidence
Finding
The skill asserts a narrow safety boundary ('only reading data already displayed' and acting like copy-paste), but elsewhere explicitly supports operation workflows, form submission, and triggering site actions. This mismatch can mislead users or downstream agents into underestimating the capability's write-side effects and consent/security implications.

Description-Behavior Mismatch

Medium
Confidence
90% confidence
Finding
The claim that 'all data stays local' and nothing is sent beyond the target site is stronger than the documented workflow justifies, because the process depends on external tooling/services and generated skills may be installed or tested through components outside the target site. Overbroad privacy claims can cause users to expose sensitive browsing/session data under false assumptions.

Intent-Code Divergence

Medium
Confidence
96% confidence
Finding
The documented 'operational boundary' says the skill only reads visible user data, yet the rest of the skill includes operation capabilities that perform actions and submissions. This creates a deceptive trust boundary: a caller may approve use expecting passive extraction while the generated workflow can execute active, state-changing behavior on third-party sites.

Intent-Code Divergence

High
Confidence
97% confidence
Finding
The template makes a trust-building claim that generated skills only read already-visible data and never bypass controls, but elsewhere explicitly supports state-changing actions such as form submission. That mismatch can mislead downstream reviewers or operators into approving automation with broader privileges than represented, increasing the chance of unauthorized or risky actions being executed under a false safety assumption.

Description-Behavior Mismatch

Medium
Confidence
93% confidence
Finding
Including reusable templates for submitting forms and performing browser-side actions expands the skill from passive exploration/extraction into active interaction. In this skill family, that broadening matters because generated artifacts could automate account actions, transactions, or content submission on arbitrary sites without clear scope controls.

Description-Behavior Mismatch

High
Confidence
99% confidence
Finding
The recommendation to open multiple stealth browser sessions with independent fingerprints is an evasion technique aimed at scaling around rate limits and detection. In the context of a browser skill generator for scraping and API discovery, this materially increases the risk of abusive collection, anti-bot circumvention, and violations of site controls.

Context-Inappropriate Capability

High
Confidence
99% confidence
Finding
Stealth browser sessions and independent fingerprints are not necessary for legitimate reusable skill packaging and instead enable concealment and anti-detection. Their inclusion signals support for bypassing operator-imposed controls, making the generated skill more dangerous than a normal exploration or automation template.

Vague Triggers

High
Confidence
88% confidence
Finding
The description defines activation conditions expansively and without clear boundaries, exclusions, or consent gates. Because this skill is designed to reverse-engineer site behavior and automate bulk extraction/operations, ambiguity around when it should activate makes misuse and overreach more likely.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The description defines activation conditions expansively and without clear boundaries, exclusions, or consent gates. Because this skill is designed to reverse-engineer site behavior and automate bulk extraction/operations, ambiguity around when it should activate makes misuse and overreach more likely.

Vague Triggers

High
Confidence
88% confidence
Finding
The instruction to use broad trigger phrases and adjacent scenarios without concrete boundaries encourages overbroad activation. For a powerful skill that forges reusable scraping and automation packages, accidental triggering can lead to unnecessary site exploration, data collection, or action generation in contexts the user did not intend.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.