Back to skill

Security audit

Chrome Debug Launcher

Security checks for vulnerabilities and agentic risk

Overview

This skill can close all existing Chrome windows and open a powerful browser-control port without enough safeguards.

Review before installing. Use this only if you are comfortable with the agent closing all current Chrome sessions, including tabs, downloads, and unsaved browser work. Do not sign into sensitive accounts in the debug profile, keep port 9222 local, and close the debug browser when finished.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:23
Finding

Overbroad Forced Termination of Existing Chrome Processes

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 12, 23, and 35
Vulnerability Type: Violation of least privilege through destructive process termination
Risk Level: Medium

Vulnerable Code

markdown
1. **Kill all Chrome processes**
powershell
# Step 1: Kill Chrome
taskkill /F /IM chrome.exe /T 2>$null
Start-Sleep -Seconds 2
bash
# Step 1: Kill Chrome
pkill -f "Google Chrome" 2>/dev/null; sleep 2

Technical Analysis

The Skill instructs the agent to forcibly terminate every matching Chrome process before opening the requested browser instances. This is broader than necessary for launching an ordinary browser and a separate debugging browser.

On Windows, /F forcibly terminates all chrome.exe processes, while /T also terminates their child processes. On macOS, pkill -f "Google Chrome" terminates processes based on a broad command-line match. Neither command limits termination to processes previously created by the Skill.

Consequently, the action crosses the task's legitimate process-control boundary and can affect unrelated browser sessions owned by the current user.

Attack Path

  1. A user submits a phrase that activates the Chrome Debug Launcher Skill.
  2. The agent follows the mandatory first step before launching either requested instance.
  3. The Windows or macOS termination command identifies every matching Chrome process.
  4. Existing interactive sessions, downloads, browser automation jobs, and child processes are forcibly terminated.
  5. Only after this disruption does the Skill launch the two new browser instances.

No elevated privilege acquisition is demonstrated. The affected scope is generally limited to Chrome processes the executing user is authorized to terminate.

Impact Assessment

Successful execution can:

  • Terminate unrelated Chrome sessions belonging to the current user.
  • Discard unsaved form input or other transie ...[truncated 425 chars]
Remediation
View remediation

Remediation Suggestions

  • Remove the instruction to kill all Chrome processes.
  • Launch each Chrome instance with a distinct --user-data-dir so that existing sessions do not need to be terminated.
  • Track the process identifiers of browser instances created by the Skill and terminate only those processes during cleanup.
  • If termination of an existing browser is unavoidable, enumerate the exact target processes and obtain explicit user confirmation before stopping them.
  • Avoid broad process-name or command-line matching such as taskkill /IM chrome.exe and pkill -f.
  • Implement graceful shutdown before forced termination and reserve forced termination for confirmed, Skill-owned processes that fail to exit.

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:28
Finding

Unauthenticated Chrome Remote-Debugging Interface on a Fixed Port

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 28-31, 38-40, and 50
Vulnerability Type: Exposed unauthenticated browser-control interface
Risk Level: High

Vulnerable Code

powershell
# Step 3: Debug Chrome (after 2s)
Start-Sleep -Seconds 2
Start-Process "C:\Program Files\Google\Chrome\Application\chrome.exe" -ArgumentList '--remote-debugging-port=9222', '--user-data-dir=C:\selenum\ChromeProfile'
bash
/Applications/Google\ Chrome.app/Contents/MacOS/Google\ Chrome \
  --remote-debugging-port=9222 \
  --user-data-dir="$HOME/selenium/ChromeProfile" &
markdown
- Connect via Selenium/Playwright: `http://localhost:9222`

Technical Analysis

Chrome's remote-debugging interface exposes the Chrome DevTools Protocol, which provides extensive control over pages in the debugging browser. The interface does not provide application-level authentication in the instructions, and the Skill does not define endpoint isolation, authorization, lifecycle cleanup, or profile sanitation.

The fixed port 9222 makes the endpoint predictable. Any untrusted process that can reach the listening endpoint may attempt to enumerate debugging targets and connect to their WebSocket debugger interfaces. Once connected, a client may inspect page content, execute JavaScript in page contexts, navigate pages, monitor network activity, and otherwise control tabs within the debugging instance.

Although the debug browser uses a separate profile, the configured paths are persistent rather than temporary. Information accumulated in that profile can therefore remain available to later debug sessions. The instructions also do not explicitly require a loopback-only binding.

Attack Path

  1. The Skill launches Chrome with --remote-debugging-port=9222.
  2. Chrome exposes its DevTools discovery and debugging endpoints on the configured port.
  3. An untrusted local process discovers or predicts port ...[truncated 1642 chars]
Remediation
View remediation

Remediation Suggestions

  • Explicitly restrict the debugging listener to loopback using the applicable Chrome option and verify the actual listening address after startup.
  • Prefer pipe-based DevTools communication, such as --remote-debugging-pipe, when supported by the automation framework.
  • Use a freshly created temporary user-data directory for each run rather than a persistent profile path.
  • Ensure the temporary profile contains no personal accounts, authentication sessions, saved credentials, or unrelated browsing data.
  • Select a dynamically allocated port instead of the predictable fixed port 9222 where TCP debugging is necessary.
  • Track the debug Chrome process and terminate it immediately when automation completes.
  • Delete the temporary profile securely after shutdown unless the user explicitly requests retention.
  • Warn the user that the Chrome DevTools Protocol is a powerful, generally unauthenticated control interface.
  • Before launch, verify that the selected port is not already occupied; after launch, verify that only the intended interface can reach it.
  • Where stronger isolation is required, run the debugging browser under a dedicated low-privilege account, sandbox, or isolated container.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (6)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill description and flow do not warn the user that invocation will forcibly terminate all existing Chrome processes. Omitting this warning materially increases harm because users cannot make an informed decision before a destructive action that may close active sessions and lose unsaved work.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The activation text includes a broad catch-all trigger such as 'any similar request,' which can cause accidental invocation of a skill that kills browser processes and opens a debugging endpoint. Because the side effects are significant, imprecise activation increases the chance of unintended disruptive or unsafe execution.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill does not warn users that it will start Chrome with a remote debugging endpoint, which is a security-sensitive capability that enables deep browser control. Without clear disclosure, users may unknowingly expose an interface that can be abused to inspect or manipulate browsing activity.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill's documented behavior includes forcibly terminating all Chrome processes before launching new instances, which goes beyond the stated purpose of simply opening two browser windows. This can cause denial of service, data loss from unsaved browser state, and interruption of unrelated user activity without explicit warning or consent.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

Force-killing every chrome.exe process is an unjustified destructive action for a launcher skill and can terminate unrelated browsing sessions, downloads, or authenticated workflows. In a skill context, this is especially risky because users may invoke it expecting only a new browser instance, not interruption of all existing Chrome activity.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The macOS instructions open a Chrome remote debugging endpoint on port 9222 but do not state any binding restrictions, authentication limits, or local-only assumptions. Exposed DevTools endpoints can allow powerful browser control, access to page contents, cookies, and automation of authenticated sessions if reachable by other local users or the network.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.