Back to skill

Security audit

Playwright Ocr

Security checks for vulnerabilities and agentic risk

Overview

This skill is a web-extraction helper, but it needs Review because it runs broad browser automation with weak containment and under-discloses setup, upload, and authenticated-page risks.

Install only in an isolated, unprivileged environment. Avoid using it on logged-in or sensitive pages unless you have explicitly reviewed what will be captured, where outputs are written, and whether any upload path is enabled. Pin dependencies, remove --no-sandbox where possible, and do not add the cron job or run sudo setup commands casually.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/extract_data.js:11
Finding

Chromium Sandbox Disabled While Processing Configurable Web Content

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:34
Finding

Unpinned Third-Party Dependencies and Privileged Installation Instructions

Content
View full analysis
Remediation
View remediation
--hash=sha256: Pillow== --hash=sha256: ``` Install it with hash verification: ```bash python3 -m pip install --require-hashes -r requirements.txt ``` 4. Separate host provisioning from Skill execution. System dependencies should be installed by an administrator through a reviewed image or provisioning process, not dynamically by the running Skill. 5. Avoid running npm, npx, or pip as root. Install application dependencies in a dedicated virtual environment or immutable container image. 6. Pin the container base image and browser artifacts by digest where containers are used. 7. Run dependency vulnerability and provenance checks in CI, and review lockfile updates before release. ]]>
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (30)

Tp4

High
Category
MCP Tool Poisoning
Confidence
89% confidence
Finding

The repeated description-behavior mismatch suggests the skill materially overstates its capability and generality. In security review terms, that is dangerous because operators cannot reliably infer what permissions, network access, or data handling practices are appropriate from the documentation provided.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding

The repeated description-behavior mismatch suggests the skill materially overstates its capability and generality. In security review terms, that is dangerous because operators cannot reliably infer what permissions, network access, or data handling practices are appropriate from the documentation provided.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

The repeated description-behavior mismatch suggests the skill materially overstates its capability and generality. In security review terms, that is dangerous because operators cannot reliably infer what permissions, network access, or data handling practices are appropriate from the documentation provided.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 57)May include surrounding context.

md
node scripts/extract_data.js --url "https://example.com/chart" --output data.json

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 123)May include surrounding context.

md
node scripts/extract_data.js --url "https://example.com/chart" --output data.json

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 204)May include surrounding context.

md
node scripts/extract_data.js --url "https://example.com/chart" --output data.json

Instruction Override

High
Category
Prompt Injection
Confidence
70% confidence
Finding

This pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 156)May include surrounding context.

bash
# Increase wait time for dynamic content
# Check selectors in extract_data.js
# Enable debug mode: export DEBUG=playwright:*

Related Skills

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/run_pipeline.py (reported line 16)May include surrounding context.

python
print(f"\n{'='*60}")
    print(f"🚀 {description}")
    print(f"{'='*60}")
    result = subprocess.run(cmd, shell=True, capture_output=False)
    return result.returncode == 0

def main():

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill documents execution of shell commands, environment-variable use, and file output, but does not declare any tool scope or permission boundaries. This makes the operational surface implicit rather than reviewable, increasing the chance that an agent invokes browser automation, writes files, or uses secrets without clear user consent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The invocation guidance is broad enough to trigger the skill for many generic web-data tasks, including authenticated pages and visual extraction, without clear boundaries. Over-broad trigger criteria increase the chance of the agent selecting this skill in contexts involving sensitive browsing sessions, credentials, or data exports that need stricter controls.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill explicitly contemplates authenticated scraping and exporting/uploading extracted data, but the description does not warn users about credential handling, sensitive-data capture, or exfiltration risks. In a browser automation skill, omission of those warnings materially increases the chance of unsafe use on private dashboards or accounts.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

Using 'npx playwright' without a pinned version allows installation or execution of whatever version is current at runtime. That weakens reproducibility and creates supply-chain risk if a bad release or dependency compromise is pulled into the environment.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The troubleshooting step again relies on unpinned 'npx playwright', exposing the environment to non-deterministic dependency resolution during support operations. Troubleshooting paths are often copy-pasted directly, so they carry the same supply-chain exposure as primary install steps.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
86% confidence
Finding

The documentation instructs users to run 'sudo apt-get install', normalizing privileged execution as part of skill setup. Encouraging root-level commands increases the blast radius of mistakes and supply-chain compromise during installation, especially in automation environments where commands may be run without careful review.

Content

Scanner excerpt · SKILL.md (reported line 147)May include surrounding context.

Issue: OCR accuracy is poor

bash
# Install additional language packs
sudo apt-get install tesseract-ocr-eng
# Use image pre-processing
python3 scripts/preprocess_image.py --input screenshot.png

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The example configuration enables automatic Feishu upload and includes concrete third-party destination identifiers, while the skill description only frames the tool as local web extraction and OCR. This creates a data-flow mismatch that can cause users to unknowingly send scraped content to an external service, increasing exfiltration and privacy risk.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

Third-party upload is not clearly necessary for Playwright/OCR extraction, so enabling it in configuration broadens the trust boundary without strong justification. In a scraping/OCR context, extracted page contents may include sensitive business, personal, or proprietary data, making silent export to Feishu materially risky.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code hardcodes toLocaleDateString('en-US', ...), which imposes a specific locale regardless of user or environment preferences. This matches the language/locale policy concern because no opt-in, fallback, or justification is provided for forcing U.S. English output.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script's human-facing description and console messages are written entirely in Chinese, which implicitly fixes the interaction language for users and operators. Under the policy, locale-specific behavior should offer user choice or clearly document a justified regional constraint.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The top-level comment states '补充缺失的周数据' ('fill missing weekly data'), which implies completing or repairing missing dataset entries. In practice, the script ignores the declared missingDates list, performs dense hover sampling across a chart, and saves collected tooltip text without actually identifying or filling the listed missing weeks.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest describes a Playwright+OCR web extraction skill with batch processing, data validation, and error recovery, but this script only navigates to a rankings page, scrapes tooltip text via DOM inspection and mouse hover, and writes raw results to disk. It performs no OCR and does not implement the claimed batch processing, validation, or recovery behaviors, making the actual operation materially narrower and different from the stated capability.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This Python file contains docstrings and printed status messages in Chinese, which effectively forces a specific language for users and operators. The policy allows locale constraints only when they are optional or clearly justified, but this file does not provide opt-in, alternatives, or documentation explaining a Chinese-only requirement.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/run_pipeline.py (reported line 16)May include surrounding context.

python
print(f"\n{'='*60}")
    print(f"🚀 {description}")
    print(f"{'='*60}")
    result = subprocess.run(cmd, shell=True, capture_output=False)
    return result.returncode == 0

def main():

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The script executes shell commands via subprocess.run with shell=True, which triggers browser automation and downstream processing. Although progress is printed, there is no explicit disclosure that external commands will be executed on the user's system, and this is safety-relevant for code files.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The changelog switches to Chinese for substantial user-facing documentation while the rest of the file is in English, without offering a language choice or documenting a locale-specific reason. This can violate language/locale policy where skills should not force a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This JSON config sets "ocr_language" to "eng", which is a natural-language locale constraint. Under the policy rule, forcing a specific language without offering a user choice or documenting justification is a language/locale policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.