Back to skill

Security audit

Actionbook

Security checks across malware telemetry and agentic risk

Overview

This skill is coherent browser-automation documentation, but it enables broad website, authenticated-session, cookie, and form-submission actions without enough user-control guidance.

Review this skill before installing if you plan to use it with logged-in websites. Only let it act on accounts, cookies, credentials, postings, bookings, purchases, or private pages when you have explicitly asked for that action and understand what data may be captured or changed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

High
Confidence
95% confidence
Finding
The skill’s activation criteria are extremely broad, covering essentially any request involving a website, including common browsing, form filling, messaging, posting, and account interactions. This increases the chance the agent will invoke powerful browser automation in situations involving sensitive data, external side effects, or higher-risk actions without sufficient narrowing, safeguards, or explicit confirmation.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill provides operational browser commands for clicking, filling, selecting, screenshotting, and extracting page text, but does not warn about privacy, credential exposure, unintended submissions, or data capture from authenticated sessions. In context, this is more dangerous because the skill is specifically designed to automate arbitrary external websites, where actions can expose personal data or cause irreversible changes.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The documentation exposes commands to list, retrieve, set, and clear browser cookies without any warning that cookies often contain session identifiers and other sensitive authentication state. In a browser-automation skill, this materially increases the chance that users or downstream agents will extract, reuse, overwrite, or delete cookies in unsafe ways, leading to session hijacking, account compromise, or accidental logout/data loss.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The reference documents page text/HTML extraction, screenshots, PDF export, snapshots, and JavaScript evaluation without warning that these commands can capture sensitive on-page content such as PII, credentials, tokens, internal documents, or account data. Because this skill is specifically intended for interacting with arbitrary websites, the omission makes accidental over-collection and exfiltration of sensitive browser data more likely.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.