Back to skill

Security audit

Browser Driver

Security checks for vulnerabilities and agentic risk

Overview

The skill is transparent about controlling the user’s logged-in browser, but it gives agents broad live-session control and recommends writing one-time secrets to a plaintext file.

Install only if you are comfortable letting the agent control your already-logged-in browser. Use a dedicated browser profile or close unrelated tabs first, confirm each high-impact action before it is submitted, avoid using the secret-to-file workflow, and make sure the debug-enabled browser and any SSH tunnel are shut down immediately afterward.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
references/selectors-and-handoffs.md:48
Finding

Predictable Plaintext Temporary File Used for One-Time Secrets

Content
View full analysis

Vulnerability Details

File Location: references/selectors-and-handoffs.md, lines 48-59
Vulnerability Type: Predictable and insecure temporary-file handling of sensitive credentials
Risk Level: Medium

Vulnerable Code:

markdown
## One-time secrets

Some values (API keys, tokens) are shown **once** in the page. Handle them without leaking:

- Pull the value out of the page text straight into a file — never echo it to chat or logs:
  ```js
  const text = await page.evaluate(() => document.body.innerText)
  const m = text.match(/<expected-pattern>/)
  require('fs').writeFileSync('secret.txt', m[0])
  ```
- Move it into the user's password manager (whatever they use), then **shred the temp file**:
  ```bash
  # store via the user's password-manager CLI, then:
  shred -u secret.txt   # or: rm -P secret.txt
  ```

Technical Analysis

The documented workflow extracts an API key or token from the authenticated browser and writes it to the fixed relative path secret.txt. This is unsafe for sensitive temporary data because:

  • The filename and location are predictable.
  • writeFileSync follows an existing symbolic link and does not use exclusive creation.
  • The resulting permissions depend on the process umask and may be broader than intended.
  • The secret remains as plaintext on disk until it is transferred and deleted.
  • shred and rm -P do not reliably erase data on copy-on-write, journaled, networked, snapshotted, or SSD-backed filesystems.
  • Cleanup is not placed in a guaranteed error-handling path, so failures may leave the secret behind.

A local process with access to the working directory could pre-create secret.txt, replace it with a symbolic link, monitor its creation, or read it before cleanup. A symbolic-link attack could also redirect the secret into another file writable by the Agent process.

Attack Path

  1. An attacker or untrusted local proces ...[truncated 1477 chars]
Remediation
View remediation

Remediation Suggestions

Prefer avoiding intermediate files entirely:

  1. Pass the secret directly to the user's password-manager CLI or API through standard input.
  2. Ensure the receiving command does not expose the secret in command-line arguments, process listings, stdout, stderr, or logs.
  3. Clear in-memory references as soon as practical and avoid returning the value through chat or tool output.

If a temporary file is unavoidable:

  1. Create a randomized private directory using fs.mkdtemp.
  2. Set the directory permissions to 0700.
  3. Create the file atomically with exclusive mode (wx) and permissions 0600.
  4. Reject existing paths and symbolic links rather than following them.
  5. Keep the file open only as long as necessary and transfer it immediately to the password manager.
  6. Place cleanup in a finally block so it executes after both success and failure.
  7. Delete the entire private temporary directory afterward.
  8. Treat deletion as lifecycle cleanup rather than guaranteed forensic erasure; account for snapshots, backups, journaling, and copy-on-write storage.

Example hardened creation pattern:

js
import fs from 'node:fs'
import os from 'node:os'
import path from 'node:path'

const dir = fs.mkdtempSync(path.join(os.tmpdir(), 'browser-driver-'))
fs.chmodSync(dir, 0o700)
const secretPath = path.join(dir, 'secret')

try {
  fs.writeFileSync(secretPath, secret, {
    flag: 'wx',
    mode: 0o600
  })

  // Transfer through a password-manager interface that does not log the value.
} finally {
  fs.rmSync(dir, { recursive: true, force: true })
}
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (11)

Credential Access

High
Category
Privilege Escalation
Confidence
97% confidence
Finding

This code example extracts a secret from the page and writes it to secret.txt, creating a plaintext credential artifact on local storage. In the context of an attached, already-authenticated browser session, the secret is likely live and high-value, and storing it in a predictable file name materially increases risk of leakage to other processes, logs, backups, or incomplete cleanup.

Content

Scanner excerpt · references/selectors-and-handoffs.md (reported line 54)May include surrounding context.

js
  const text = await page.evaluate(() => document.body.innerText)
  const m = text.match(/<expected-pattern>/)
  require('fs').writeFileSync('secret.txt', m[0])
  • Move it into the user's password manager (whatever they use), then shred the temp file:
    bash

Credential Access

High
Category
Privilege Escalation
Confidence
93% confidence
Finding

The shredding/removal instruction acknowledges a local plaintext secret file exists, but deletion is not a reliable security boundary on modern systems due to journaling filesystems, cloud sync, backups, EDR, or platform differences. Presenting shred -u secret.txt or rm -P secret.txt as cleanup can create false confidence while normalizing unsafe credential handling.

Content

Scanner excerpt · references/selectors-and-handoffs.md (reported line 59)May include surrounding context.

  • Move it into the user's password manager (whatever they use), then shred the temp file:
    bash
    # store via the user's password-manager CLI, then:
    shred -u secret.txt   # or: rm -P secret.txt
    
  • Do not paste the secret back into the conversation, even truncated.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill explicitly instructs the agent to capture one-time secrets from the user's live authenticated browser session and write them to a file, but it does not require a prominent privacy warning, explicit consent for secret handling, retention limits, or safeguards against local exposure. In the context of a browser-driving skill attached to a real logged-in session, this materially increases the risk of credential leakage through temp files, logs, screenshots, shell history, or accidental agent disclosure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The instructions explicitly tell the agent to quit and relaunch the user's real browser with remote debugging enabled and session restoration, which grants automation access to the user's live authenticated context across tabs. Without a prominent consent, scope, and privacy warning, this can expose unrelated accounts, sensitive tabs, cookies, and in-session data far beyond the immediate task.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
84% confidence
Finding

Using nohup to detach a browser launched with a remote debugging port leaves a powerful control interface running independently of the initiating shell. If not tightly bounded to localhost, short-lived use, and explicit cleanup, this can extend the window in which any local process or misconfiguration can hijack the user's authenticated browser session.

Content

Scanner excerpt · references/launch-and-drive.md (reported line 16)May include surrounding context.

  1. Launch the binary directly with the debug port. Do not rely on open -a "<App>" --args --remote-debugging-port=... right after a quit — there is a race where the app has not fully exited, so it either does not start or silently drops the flag. Launch the executable directly and detach it:
    bash
    nohup "/Applications/Microsoft Edge.app/Contents/MacOS/Microsoft Edge" \
      --remote-debugging-port=9223 --restore-last-session \
      >/dev/null 2>&1 &
    

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The file encourages opening pages, navigating with carried-over sessions, and performing mutating actions, but does not clearly warn that these actions may change account state, submit transactions, or trigger irreversible operations. In a live authenticated browser, even small mistakes can alter user data or perform privileged actions under the user's identity.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly recommends writing one-time secrets from the page into a local file and then deleting it, but does not warn that disk writes can leave recoverable traces, fail to delete, or be exposed through backups, indexing, shell history, or endpoint monitoring. Because the skill attaches to the user's real authenticated browser, any captured API key or token is likely valid and sensitive, making transient file creation a meaningful credential exposure risk.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The documentation instructs the agent to extract one-time secrets into a local file and move them via a password-manager CLI, which broadens the skill from browser-driving into credential handling on the host. In a browser attached to a live logged-in session, this creates unnecessary secret exposure on disk and in adjacent tools if anything fails, is logged, or is accessed by other local processes.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The manifest frames this skill as attaching to the user's browser over CDP and handling browser-driven handoffs. Recommending checks against a separate 'source-of-truth API/CLI' introduces a broader capability outside browser automation, which is not clearly justified by the stated purpose of this skill.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The cleanup section includes OS-level commands to quit and reopen the browser, which exceeds a narrowly scoped CDP attachment role and can disrupt the user's environment. In the context of a live personal browser session, forced app control may close unrelated tabs or interrupt active work without sufficient warning or consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The restart guidance tells the operator to quit and reopen the browser to close the remote-debugging port, but omits a clear warning that this will terminate the user's active browser session and may close unrelated tabs or windows. In a skill meant to operate on the user's own live browser, failing to warn about this side effect can cause accidental disruption or data loss.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.