Back to skill

Security audit

Save All Resource

Security checks for vulnerabilities and agentic risk

Overview

The skill has a coherent browser-capture purpose, but a visited site could make it write outside the intended Desktop folder or consume large amounts of disk and memory.

Install only if you understand that it records raw same-origin website responses to disk. Use it only on sites you are authorized to archive, avoid logged-in or sensitive sessions, monitor disk usage, and review/fix the path containment and capture quota issues before using it on untrusted websites.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/main.js:100
Finding

Path Traversal Enables Writes Outside the Intended Output Directory

Content
View full analysis
sanitizeFilename(segment)) .join('/') .replace(/^\/+/, ''); } function writeTextFile(url, contentType, text) { const localPath = urlToLocalPath(url, contentType); const filePath = path.join(outputDir, localPath); ensureDir(filePath); fs.writeFileSync(filePath, text, 'utf8'); logInfo('✔ text', localPath); } function writeBinaryFile(url, contentType, buffer) { const localPath = urlToLocalPath(url, contentType); const filePath = path.join(outputDir, localPath); ensureDir(filePath); fs.writeFileSync(filePath, buffer); logInfo('✔ bin ', localPath); } ``` ### Technical Analysis The local filename is derived from an attacker-influenced response URL. The code applies `decodeURIComponent()` to the URL pathname before converting it into a filesystem path. Encoded path separators can therefore become literal separators after URL parsing. Although each segment is passed through `sanitizeFilename()`, that function only replaces reserved characters and control characters. It does not reject the special filesystem segments `.` and `..`. Consequently, a pathname conta ...[truncated 2000 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/main.js:150
Finding

Unbounded Response Capture Allows Disk and Memory Exhaustion

Content
View full analysis
= 400) return; if (!shouldSaveUrl(responseUrl)) return; if (savedResources.has(responseUrl)) return; savedResources.add(responseUrl); const headers = response.headers(); const contentType = headers['content-type'] || ''; try { if (isTextLikeContent(contentType, resourceType)) { const text = await response.text(); writeTextFile(responseUrl, contentType, text); return; } const buffer = await response.buffer(); writeBinaryFile(responseUrl, contentType, buffer); } catch (err) { logError('✖ response save failed:', responseUrl, err.message); } } ``` ### Technical Analysis Every accepted response is read completely into process memory through either `response.text()` or `response.buffer()` and is then written to disk. The implementation does not enforce: - A maximum response size. - A maximum aggregate capture size. - A maximum number of saved resources. - A maximum capture duration. - A minimum free-disk-space threshold. - A bound on concurrent response processing. The `savedResources` set only prevents saving the same exact URL more than once. An attacker can bypass this safeguard by generating arbitrary unique URLs, such as by changing path components or query parameters. The set itself also grows without a limit for the lifetime of the process. Because the browser is intentionally kept alive until the user closes the tab, a hostile page can continuously issue same-origin requests and cause both disk usage and process memory ...[truncated 1214 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (10)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

Captured network responses can include sensitive data such as authenticated HTML, API JSON, account details, tokens reflected in responses, downloaded documents, or other private content visible during browsing. Because the skill saves raw same-origin responses automatically and continuously, failing to warn about sensitive-data capture materially increases the chance of unintended local exfiltration, retention, or later disclosure.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: basic-ftp==5.2.0 — 4 advisory(ies): GHSA-6v7q-wjvx-w8wg (basic-ftp: Incomplete CRLF Injection Protection Allows Arbitrary FTP Command Exe); CVE-2026-39983 (basic-ftp has FTP Command Injection via CRLF); CVE-2026-41324 (basic-ftp vulnerable to denial of service via unbounded memory consumption in Cl) +1 more

High
Category
Supply Chain
Confidence
80% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: extract-zip==2.0.1 — 2 advisory(ies): CVE-2026-19693 (extract-zip allows arbitrary file writes through symlink archive entries); CVE-2026-56876 (extract-zip unvalidated symlink path traversal)

High
Category
Supply Chain
Confidence
80% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: ip-address==10.1.0 — 2 advisory(ies): CVE-2026-69192 (ip-address: Address4 decodes leading-zero octets as decimal while resolvers deco); CVE-2026-42338 (ip-address has XSS in Address6 HTML-emitting methods)

High
Category
Supply Chain
Confidence
80% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: js-yaml==4.1.1 — 4 advisory(ies): CVE-2026-84375 (js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources); CVE-2026-59869 (js-yaml: YAML merge-key chains can force quadratic CPU consumption); GHSA-5p4m-2wfm-xmqj (JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026) +1 more

High
Category
Supply Chain
Confidence
80% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: ws==8.19.0 — 2 advisory(ies): CVE-2026-45736 (ws: Uninitialized memory disclosure); CVE-2026-48779 (ws: Memory exhaustion DoS from tiny fragments and data chunks)

High
Category
Supply Chain
Confidence
92% confidence
Finding

ws is a direct transitive dependency of puppeteer-core and is likely exercised during browser automation because Puppeteer communicates with Chromium over WebSocket-based DevTools/BiDi channels. A memory disclosure or memory-exhaustion flaw in that channel can affect the local automation process, and this skill is already high-risk in context because it continuously captures raw same-origin responses to local disk, making a compromise of the browser-control path more consequential.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly captures and continuously saves all same-origin network responses to a local Desktop folder, but the user-facing description does not present this as a clear privacy/storage warning. This creates a real risk that users will trigger broad collection of website content without understanding the scope or persistence of what is being stored locally.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

All user-facing instructions and the manifest description are written in Chinese, with no indication that another language is available or that the locale restriction is intentional and justified. Under the stated policy, language constraints should be optional or clearly documented as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

This JavaScript file contains natural-language comments and user-facing console messages in Chinese, including operational instructions later in the file, without offering any language choice or opt-in. That can violate a language/locale policy when a skill is expected to be usable in the user's preferred language.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · scripts/package.json (reported line 10)May include surrounding context.

json
"license": "ISC",
  "type": "module",
  "dependencies": {
    "puppeteer": "^24.39.1"
  }
}

Static analysis

No suspicious patterns detected.