Back to skill

Security audit

Agent Browser

Security checks for vulnerabilities and agentic risk

Overview

This browser automation skill is not clearly malicious, but it needs Review because it can handle login sessions, cookies, storage, JavaScript execution, and mutable global installation without adequate safeguards.

Install only in workflows where broad browser automation is appropriate. Treat saved state files, cookies, localStorage output, screenshots, PDFs, traces, and recordings as sensitive; avoid saving privileged sessions, keep state files out of repositories, restrict permissions, and delete them when finished. Prefer a pinned reviewed package version or commit instead of installing the latest global package blindly.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:16
Finding

Unpinned Third-Party Package Installation and Mutable Source Build

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:16-31; CONTRIBUTING.md:22-26
Vulnerability Type: Supply-chain exposure through unpinned dependencies and mutable sources
Risk Level: Medium

Vulnerable Code

SKILL.md:16-31:

bash
## Installation

### npm recommended

```bash
npm install -g agent-browser
agent-browser install
agent-browser install --with-deps

From Source

bash
git clone https://github.com/vercel-labs/agent-browser
cd agent-browser
pnpm install
pnpm build
text

`CONTRIBUTING.md:22-26`:

```bash
1. Install the latest version
   ```bash
   npm install -g agent-browser@latest
   ```

Technical Analysis

The documented installation procedures retrieve and execute third-party software without pinning a reviewed package version, source commit, or integrity digest. npm install -g agent-browser resolves the package version at installation time, while agent-browser@latest explicitly tracks a mutable distribution tag. The source-build procedure similarly clones the repository's mutable default branch.

Package installation can execute npm lifecycle scripts from the package or its transitive dependencies. The source workflow also runs dependency installation and build logic from content that may have changed after this Skill was reviewed. Installing the npm package globally makes its executable available throughout the user's environment and may increase the consequences of a supply-chain compromise.

No evidence establishes that the current upstream package or repository is malicious. The vulnerability is the absence of controls ensuring that users install the same reviewed artifact.

Attack Path

  1. An attacker compromises the upstream package, a maintainer account, the source repository, or a transitive dependency.
  2. The attacker publishes a malicious release under the latest tag or modifies the repository's default branch.

...[truncated 778 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin agent-browser to a specifically reviewed version rather than using an implicit current version or @latest.
  • Pin source installations to a full reviewed commit hash or signed release tag.
  • Publish and verify expected integrity hashes or signatures for downloaded artifacts.
  • Use a committed lockfile and frozen-lockfile installation mode for source builds.
  • Review lifecycle scripts and dependency changes before upgrading.
  • Prefer a project-local, least-privilege installation over a global installation where practical.
  • Document that users should not run installation commands with administrative privileges unless strictly required.
  • Establish a controlled upgrade process that reviews and tests each new upstream version before updating the pinned reference.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:232
Finding

Authentication Session State Persisted Without Security Safeguards

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:232-266
Vulnerability Type: Insecure storage of authentication session material
Risk Level: Medium

Vulnerable Code

SKILL.md:232-266:

bash
### State management

```bash
agent-browser state save auth.json    # Save session state
agent-browser state load auth.json    # Load saved state

Example: Form submission

bash
agent-browser open https://example.com/form
agent-browser snapshot -i
# Output shows: textbox "Email" [ref=e1], textbox "Password" [ref=e2], button "Submit" [ref=e3]

agent-browser fill @e1 "user@example.com"
agent-browser fill @e2 "password123"
agent-browser click @e3
agent-browser wait --load networkidle
agent-browser snapshot -i  # Check result

Example: Authentication with saved state

bash
# Login once
agent-browser open https://app.example.com/login
agent-browser snapshot -i
agent-browser fill @e1 "username"
agent-browser fill @e2 "password"
agent-browser click @e3
agent-browser wait --url "/dashboard"
agent-browser state save auth.json

# Later sessions: load saved state
agent-browser state load auth.json
agent-browser open https://app.example.com/dashboard
text

### Technical Analysis

The recommended authentication workflow saves browser state to a predictably named file, `auth.json`, in the current working directory. Browser state commonly includes cookies or storage values capable of representing an authenticated session. The documentation does not warn that the file may contain sensitive session material, require restrictive filesystem permissions, direct users to store it outside repositories, provide an ignore rule, or instruct users to remove it after use.

If the saved state contains a reusable session token, possession of the file may be sufficient to assume the authenticated browser session without knowing the user's password. The exact contents and protection
...[truncated 1320 chars]
Remediation
View remediation

Remediation Suggestions

  • Explicitly identify saved browser state as sensitive authentication material.
  • Store state outside the project directory in a dedicated secrets or runtime-state directory.
  • Create the file with owner-only permissions, such as mode 0600 on compatible systems.
  • Add auth.json and equivalent state-file patterns to .gitignore and artifact-exclusion rules.
  • Use a randomized or user-selected secure path instead of a predictable file in the current directory.
  • Encrypt persisted state at rest where the CLI or surrounding workflow supports it.
  • Delete the state file promptly when it is no longer needed.
  • Use short-lived sessions and revoke exposed sessions immediately.
  • Avoid saving highly privileged administrative sessions.
  • Add an example cleanup command and a prominent warning adjacent to every state save example.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (8)

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · CONTRIBUTING.md (reported line 60)May include surrounding context.

md
## Adding New Commands to the Skill

Update SKILL.md when the upstream CLI adds new commands.
- Keep the Installation section
- Add new commands in the correct category
- Include usage examples

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest description frames the skill as simple navigation/click/type/snapshot automation, but the body documents substantially broader capabilities including arbitrary JavaScript execution, network interception/mocking, credential injection, storage manipulation, CDP attachment, and session-state persistence. This understatement can mislead agents or operators into granting the skill in lower-trust contexts than warranted, increasing the chance of unauthorized state changes or sensitive data access.

Content

No source excerpt is available for this finding.

Context Window Stuffing

Medium
Category
Memory Poisoning
Confidence
85% confidence
Finding

Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.

Content

Scanner excerpt · SKILL.md (reported line 41)May include surrounding context.

agent-browser open # Navigate to page agent-browser snapshot -i # Get interactive elements with refs agent-browser click @e1 # Click element by ref agent-browser fill @e2 "text" # Fill input by ref agent-browser close # Close browser

text

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill documents saving screenshots/PDFs and especially session state to local files without warning that these artifacts may contain credentials, cookies, personal data, or other sensitive content. Persisting such material silently increases the risk of credential theft, unintended retention, and later reuse by other processes or users.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill exposes operations for setting HTTP basic auth credentials, reading/modifying cookies, and reading/modifying localStorage without any guidance about sensitivity or access control. In browser automation, these primitives can directly expose or alter authentication state, enabling account takeover, session hijacking, or leakage of secrets to logs and files.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documented agent-browser eval "document.title" capability enables arbitrary JavaScript execution in the page context, which is materially more powerful than ordinary browser automation. In an agent setting, this can be abused to read sensitive DOM data, manipulate application state, trigger privileged actions, or access tokens available to page scripts.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
90% confidence
Finding

Saving and loading browser state enables persistence and reuse of authenticated sessions across runs. In an agent environment, that increases the blast radius of compromise because stolen or mishandled state files can grant direct access to accounts without reauthentication.

Content

Scanner excerpt · SKILL.md (reported line 236)May include surrounding context.

bash
agent-browser state save auth.json    # Save session state
agent-browser state load auth.json    # Load saved state

Example: Form submission

Session Persistence

Medium
Category
Rogue Agent
Confidence
90% confidence
Finding

The authentication example normalizes saving auth.json and reloading it later, which operationalizes session persistence for authenticated contexts without any caution about secret handling. This makes misuse more likely because users may treat reusable login state as routine rather than highly sensitive credential material.

Content

Scanner excerpt · SKILL.md (reported line 265)May include surrounding context.

agent-browser wait --url "/dashboard" agent-browser state save auth.json

Later sessions: load saved state

agent-browser state load auth.json agent-browser open https://app.example.com/dashboard

text

Static analysis

No suspicious patterns detected.