Back to skill

Security audit

Browser Act

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed browser automation skill, but its activation rules are broad enough that it could steer agents into using a powerful browser/session tool for ordinary web tasks.

Install only if you want an agent to use the browser-act CLI as a primary browser automation path. Review when it will be invoked, keep confirmation prompts enabled for login, form submission, file upload, browser creation, and deletion, and prefer simpler read-only web tools for ordinary page fetching unless browser rendering or session automation is actually needed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The skill description contains very broad activation criteria such as generic browsing, fetching, extraction, screenshots, and web automation tasks. This can cause the agent to invoke the skill in many ordinary web-related situations, expanding the tool’s reach beyond user intent and increasing the chance of unnecessary network access, browser session creation, or interaction with sensitive authenticated content.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.