T08 · Insecure Dependencies
- Location
SKILL.md:4- Finding
Unpinned Third-Party Tools Can Introduce Supply-Chain Code Execution
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This browser automation skill is coherent, but it needs review because it can reuse logged-in browser sessions, persist authentication state, run page scripts, and execute unpinned tooling.
Install only if you trust the `agent-browser` package source and need high-privilege browser automation. Prefer a pinned, verified binary; use dedicated browser profiles instead of your normal logged-in Chrome; enable domain allowlists, content boundaries, and action policy; encrypt or delete state files; avoid recording or profiling sensitive login/account workflows; and do not use proxy rotation to bypass site rules.
SKILL.md:4Unpinned Third-Party Tools Can Introduce Supply-Chain Code Execution
SKILL.md:55Authentication Cookies and Tokens Are Persisted in Plaintext State Files by Default
Connecting to an existing Chrome session and importing auth state can grant the agent access to the user's already-authenticated accounts, cookies, and browsing context beyond the requested site. That materially increases the blast radius from single-site automation to compromise of unrelated sessions and sensitive accounts.
The auth vault stores and reuses credentials, expanding the skill from browser automation into secret management. If misused or compromised, it enables persistent access to accounts and can centralize sensitive credentials in a way that exceeds the manifest's declared purpose.
Session recording can capture sensitive on-screen data, typed credentials, tokens, personal information, and authenticated workflows, then persist them to disk. In an agent context, this is especially risky because recordings may outlive the task and be accessible to other processes or users.
agent-browser --headed open https://example.com agent-browser highlight @e1 # Highlight element agent-browser inspect # Open Chrome DevTools for the active page agent-browser record start demo.webm # Record session agent-browser profiler start # Start Chrome DevTools profiling agent-browser profiler stop trace.json # Stop and save profile (path optional)
The documentation explicitly instructs users to start Chrome with --remote-debugging-port and then export cookies and localStorage from a live authenticated browser session. Even though it includes a warning, this pattern materially increases exposure because any local process can attach to the debugging interface and extract session data, which is especially sensitive in an agent-browser skill designed to automate authenticated browsing.
ication](#restoring-authentication)
The fastest way to authenticate is to reuse cookies from a Chrome session you are already logged into.
Step 1: Start Chrome with remote debugging
# macOS
"/Applications/Google Chrome.app/Contents/MacOS/Google Chrome" --remote-debugging-port=9222
# Linux
google-chrome --remote-debugging-port=9222
# Windows
"C:\Program Files\Google\Chrome\Application\chrome.exe" --remote-debugging-port=9222
Log in to your target site(s) in this Chrome window as you normally would.
Security note:
--remote-debugging-portexposes full browser control on localhost. Any local process can connect and read cookies, execute JS, etc.
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
Clean up after automation
agent-browser cookies clear
rm -f ./auth-state.json
Use short-lived sessions for CI/CD
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
echo "*.auth-state.json" >> .gitignore
rm /tmp/auth-state.json
### 4. Timeout Long Sessions
The skill manifest references npx agent-browser without a version pin, which permits execution of whatever version is current at invocation time. In an agent setting, that expands risk from ordinary dependency drift to remote code execution through package compromise or typosquat/update hijack.
The trigger language is very broad and can cause the skill to activate for generic web-related tasks without sufficient scoping or user intent verification. Over-broad invocation increases the chance an agent uses a highly privileged browser automation tool when a lower-risk alternative would suffice.
The manifest allows execution via npx agent-browser:* without pinning a specific package version. That creates a supply-chain risk: a future malicious or compromised package release could be fetched and executed at runtime under the agent's privileges.
The documentation normalizes sensitive authentication workflows such as state files, persistent profiles, and imported sessions, but warnings are not sufficiently prominent relative to the risk. In practice, this can lead agents or operators to expose plaintext tokens, reusable sessions, or credential material without appreciating the consequences.
Direct clipboard read/write lets the skill access data unrelated to the active website automation task, including secrets a user copied previously. In an agent environment this creates a cross-context data exposure path that exceeds the declared browser automation scope.
The documented eval capability permits arbitrary JavaScript execution in the browser context, which is broader than simple navigation and form interaction. This can access page DOM, tokens, storage, and potentially facilitate data exfiltration or unsafe actions on authenticated sites beyond the manifest's stated purpose.
Project-level persistent configuration that includes browser profile paths encourages storage and reuse of session-bearing browser data across runs. That persistence increases the chance of unintended credential/session retention, cross-task contamination, or leakage from the workspace.
Create agent-browser.json in the project root for persistent settings:
{
This markdown file includes concrete authentication examples using literal passwords and tokens, such as filling a password field with a hardcoded value and later setting a cookie token directly. Although the document has broader security notes elsewhere, these specific sections do not warn readers near the examples about handling credentials and tokens safely, which could affect user data and account security.
Request inspection plus custom headers and credentials can expose API tokens, authorization headers, or other secrets in transit or in logs. Without clear warnings, an agent or user may unintentionally send sensitive data to unintended origins or store it in command history and artifacts.
Cookie and localStorage commands expose and modify sensitive browser data, including session identifiers, CSRF tokens, and application secrets often stored client-side. Documenting these features without privacy and destructive-operation warnings increases the chance of accidental leakage, unauthorized manipulation, or service disruption during agent use.
The manifest frames the skill as a browser automation CLI for navigation, form interaction, screenshots, extraction, and testing. This command reference additionally documents eval modes that allow arbitrary JavaScript execution, including unrestricted scripts via base64 or stdin, which is materially broader than the user-facing description of standard browser actions.
Saving and restoring browser state can capture cookies, localStorage, and authentication artifacts that may persist active sessions or credentials on disk. Without warnings or handling guidance, users may unintentionally create reusable session files that can be copied, exfiltrated, or reused for account access.
Restoring previously saved browser state enables session persistence and replay, which can bypass fresh authentication and rehydrate privileged sessions. In an agent-browser skill, this is especially sensitive because it enables durable access across tasks, users, or environments if state files are reused improperly.
agent-browser state save auth.json # Save cookies, storage, auth state
agent-browser state load auth.json # Restore saved state
The documented --extension <path> option allows the skill to load arbitrary browser extensions. Extension loading can significantly expand runtime capabilities beyond ordinary website interaction and is not justified or mentioned by the manifest's stated purpose of browser automation for navigation, forms, screenshots, scraping, and testing.
The documentation encourages capturing and saving Chrome performance traces but does not warn that trace files can include sensitive information such as visited URLs, timing patterns, interaction sequences, script execution details, and potentially application-specific identifiers. In an agent-driven browser automation context, users may profile authenticated sessions or internal apps, increasing the chance that traces are stored insecurely, shared in CI artifacts, or exposed to unauthorized parties.
The authenticated proxy example embeds credentials directly in a proxy URL stored in environment variables, without warning that such secrets may leak through shell history, process inspection, crash reports, or logs. This creates a realistic credential exposure risk, especially in shared shells, CI systems, and agent execution environments.
The documentation explicitly recommends rotating proxies to avoid rate limiting during scraping, which facilitates evasive behavior against target site controls. In the context of a browser-automation skill, this goes beyond neutral proxy configuration and can enable policy-violating or abusive collection at scale.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
# Restore saved state
agent-browser state load /path/to/auth-state.json
# Continue with authenticated session
The documentation strongly encourages recording browser sessions and saving screenshots/videos to disk, including login and test workflows, but provides no warning that these artifacts may capture credentials, session tokens, personal data, or other sensitive application content. In an agent-browser skill, this is more dangerous because the tool is explicitly used for web interaction and automation, often against authenticated applications, making accidental sensitive-data retention and exfiltration more likely.
No suspicious patterns detected.