Back to skill

Security audit

opencli-browser-sitemap

Security checks for vulnerabilities and agentic risk

Overview

This skill gives bounded guidance for using sitemap files during OpenCLI browser automation and only writes disclosed local sitemap notes.

Before installing, understand that the skill can guide an agent to perform OpenCLI browser workflows and write local sitemap overlay notes. This behavior is expected for the skill, but users should still review any website action before allowing state-changing browser or adapter commands.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.