Back to skill

Security audit

Agent Browser

Security checks for vulnerabilities and agentic risk

Overview

This browser automation skill is coherent, but it needs review because it can reuse logged-in browser sessions, persist authentication state, run page scripts, and execute unpinned tooling.

Install only if you trust the `agent-browser` package source and need high-privilege browser automation. Prefer a pinned, verified binary; use dedicated browser profiles instead of your normal logged-in Chrome; enable domain allowlists, content boundaries, and action policy; encrypt or delete state files; avoid recording or profiling sensitive login/account workflows; and do not use proxy rotation to bypass site rules.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:4
Finding

Unpinned Third-Party Tools Can Introduce Supply-Chain Code Execution

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:55
Finding

Authentication Cookies and Tokens Are Persisted in Plaintext State Files by Default

Content
View full analysis
[state-file]}" STATE_FILE="${2:-./auth-state.json}" echo "Authentication workflow: $LOGIN_URL" if [[ -f "$STATE_FILE" ]]; then echo "Loading saved state from $STATE_FILE..." if agent-browser --state "$STATE_FILE" open "$LOGIN_URL" 2>/dev/null; then ``` The customizable login flow saves the state without enforcing encryption or restrictive permissions: ```bash # echo "Saving state to $STATE_FILE" # agent-browser state save "$STATE_FILE" ``` ### Technical Analysis The skill instructs users to export browser cookies and local storage into state files and later reload those files to restore authenticated sessions. According to the project’s own documentation, these files contain session tokens in plaintext unless `AGENT_BROWSER_ENCRYPTION_KEY` is separately configured. The default filenames, `./auth.json` and `./auth-state.json`, are located in the ...[truncated 2383 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
Findings (28)

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

Connecting to an existing Chrome session and importing auth state can grant the agent access to the user's already-authenticated accounts, cookies, and browsing context beyond the requested site. That materially increases the blast radius from single-site automation to compromise of unrelated sessions and sensitive accounts.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
94% confidence
Finding

The auth vault stores and reuses credentials, expanding the skill from browser automation into secret management. If misused or compromised, it enables persistent access to accounts and can centralize sensitive credentials in a way that exceeds the manifest's declared purpose.

Content

No source excerpt is available for this finding.

Context Leakage

High
Category
Data Exfiltration
Confidence
85% confidence
Finding

Session recording can capture sensitive on-screen data, typed credentials, tokens, personal information, and authenticated workflows, then persist them to disk. In an agent context, this is especially risky because recordings may outlive the task and be accessible to other processes or users.

Content

Scanner excerpt · SKILL.md (reported line 326)May include surrounding context.

agent-browser --headed open https://example.com agent-browser highlight @e1 # Highlight element agent-browser inspect # Open Chrome DevTools for the active page agent-browser record start demo.webm # Record session agent-browser profiler start # Start Chrome DevTools profiling agent-browser profiler stop trace.json # Stop and save profile (path optional)

text

YARA rule 'info_stealer': Information stealer patterns (credential harvesting, browser data theft) [malware]

High
Category
YARA Match
Confidence
89% confidence
Finding

The documentation explicitly instructs users to start Chrome with --remote-debugging-port and then export cookies and localStorage from a live authenticated browser session. Even though it includes a warning, this pattern materially increases exposure because any local process can attach to the debugging interface and extract session data, which is especially sensitive in an agent-browser skill designed to automate authenticated browsing.

Content

Scanner excerpt · references/authentication.md (reported line 24)May include surrounding context.

ication](#restoring-authentication)

Import Auth from Your Browser

The fastest way to authenticate is to reuse cookies from a Chrome session you are already logged into.

Step 1: Start Chrome with remote debugging

bash
# macOS
"/Applications/Google Chrome.app/Contents/MacOS/Google Chrome" --remote-debugging-port=9222

# Linux
google-chrome --remote-debugging-port=9222

# Windows
"C:\Program Files\Google\Chrome\Application\chrome.exe" --remote-debugging-port=9222

Log in to your target site(s) in this Chrome window as you normally would.

Security note: --remote-debugging-port exposes full browser control on localhost. Any local process can connect and read cookies, execute JS, etc.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/authentication.md (reported line 294)May include surrounding context.

  1. Clean up after automation

    bash
    agent-browser cookies clear
    rm -f ./auth-state.json
    
  2. Use short-lived sessions for CI/CD

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/session-management.md (reported line 185)May include surrounding context.

echo "*.auth-state.json" >> .gitignore

Delete after use

rm /tmp/auth-state.json

text

### 4. Timeout Long Sessions

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The skill manifest references npx agent-browser without a version pin, which permits execution of whatever version is current at invocation time. In an agent setting, that expands risk from ordinary dependency drift to remote code execution through package compromise or typosquat/update hijack.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger language is very broad and can cause the skill to activate for generic web-related tasks without sufficient scoping or user intent verification. Over-broad invocation increases the chance an agent uses a highly privileged browser automation tool when a lower-risk alternative would suffice.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The manifest allows execution via npx agent-browser:* without pinning a specific package version. That creates a supply-chain risk: a future malicious or compromised package release could be fetched and executed at runtime under the agent's privileges.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The documentation normalizes sensitive authentication workflows such as state files, persistent profiles, and imported sessions, but warnings are not sufficiently prominent relative to the risk. In practice, this can lead agents or operators to expose plaintext tokens, reusable sessions, or credential material without appreciating the consequences.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

Direct clipboard read/write lets the skill access data unrelated to the active website automation task, including secrets a user copied previously. In an agent environment this creates a cross-context data exposure path that exceeds the declared browser automation scope.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documented eval capability permits arbitrary JavaScript execution in the browser context, which is broader than simple navigation and form interaction. This can access page DOM, tokens, storage, and potentially facilitate data exfiltration or unsafe actions on authenticated sites beyond the manifest's stated purpose.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
78% confidence
Finding

Project-level persistent configuration that includes browser profile paths encourages storage and reuse of session-bearing browser data across runs. That persistence increases the chance of unintended credential/session retention, cross-task contamination, or leakage from the workspace.

Content

Scanner excerpt · SKILL.md (reported line 574)May include surrounding context.

Configuration File

Create agent-browser.json in the project root for persistent settings:

json
{

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file includes concrete authentication examples using literal passwords and tokens, such as filling a password field with a hardcoded value and later setting a cookie token directly. Although the document has broader security notes elsewhere, these specific sections do not warn readers near the examples about handling credentials and tokens safely, which could affect user data and account security.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

Request inspection plus custom headers and credentials can expose API tokens, authorization headers, or other secrets in transit or in logs. Without clear warnings, an agent or user may unintentionally send sensitive data to unintended origins or store it in command history and artifacts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Cookie and localStorage commands expose and modify sensitive browser data, including session identifiers, CSRF tokens, and application secrets often stored client-side. Documenting these features without privacy and destructive-operation warnings increases the chance of accidental leakage, unauthorized manipulation, or service disruption during agent use.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest frames the skill as a browser automation CLI for navigation, form interaction, screenshots, extraction, and testing. This command reference additionally documents eval modes that allow arbitrary JavaScript execution, including unrestricted scripts via base64 or stdin, which is materially broader than the user-facing description of standard browser actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Saving and restoring browser state can capture cookies, localStorage, and authentication artifacts that may persist active sessions or credentials on disk. Without warnings or handling guidance, users may unintentionally create reusable session files that can be copied, exfiltrated, or reused for account access.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
91% confidence
Finding

Restoring previously saved browser state enables session persistence and replay, which can bypass fresh authentication and rehydrate privileged sessions. In an agent-browser skill, this is especially sensitive because it enables durable access across tasks, users, or environments if state files are reused improperly.

Content

Scanner excerpt · references/commands.md (reported line 216)May include surrounding context.

bash
agent-browser state save auth.json    # Save cookies, storage, auth state
agent-browser state load auth.json    # Restore saved state

Global Options

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
76% confidence
Finding

The documented --extension <path> option allows the skill to load arbitrary browser extensions. Extension loading can significantly expand runtime capabilities beyond ordinary website interaction and is not justified or mentioned by the manifest's stated purpose of browser automation for navigation, forms, screenshots, scraping, and testing.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documentation encourages capturing and saving Chrome performance traces but does not warn that trace files can include sensitive information such as visited URLs, timing patterns, interaction sequences, script execution details, and potentially application-specific identifiers. In an agent-driven browser automation context, users may profile authenticated sessions or internal apps, increasing the chance that traces are stored insecurely, shared in CI artifacts, or exposed to unauthorized parties.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The authenticated proxy example embeds credentials directly in a proxy URL stored in environment variables, without warning that such secrets may leak through shell history, process inspection, crash reports, or logs. This creates a realistic credential exposure risk, especially in shared shells, CI systems, and agent execution environments.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documentation explicitly recommends rotating proxies to avoid rate limiting during scraping, which facilitates evasive behavior against target site controls. In the context of a browser-automation skill, this goes beyond neutral proxy configuration and can enable policy-violating or abusive collection at scale.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
55% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/session-management.md (reported line 55)May include surrounding context.

Load Session State

bash
# Restore saved state
agent-browser state load /path/to/auth-state.json

# Continue with authenticated session

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documentation strongly encourages recording browser sessions and saving screenshots/videos to disk, including login and test workflows, but provides no warning that these artifacts may capture credentials, session tokens, personal data, or other sensitive application content. In an agent-browser skill, this is more dangerous because the tool is explicitly used for web interaction and automation, often against authenticated applications, making accidental sensitive-data retention and exfiltration more likely.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.