Back to skill

Security audit

Browser Automation Zero Token

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent browser-automation guide, but it under-discloses the risk of saving reusable logged-in browser sessions to a plain local auth file.

Review before installing or using this skill on important accounts. If you use saved browser state, treat the state file like a password: keep it outside project folders, restrict file permissions, never commit or share it, use separate files per site/account, and delete or revoke sessions when no longer needed. Pin and verify agent-browser where possible before installing global dependencies.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:68
Finding

Unpinned Global Installation of Third-Party Packages and System Dependencies

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:68-80
Vulnerability Type: Supply-chain exposure through unpinned third-party installations
Risk Level: Medium

Vulnerable Code

bash
npm install -g agent-browser
agent-browser install --with-deps
agent-browser --version

Optional ecosystem install:

bash
clawhub install openclaw-skills-browserautomation-skill

Technical Analysis

The installation instructions retrieve the latest available versions of agent-browser, its browser or system dependencies, and an optional ClawHub package without specifying immutable versions or integrity hashes. The global npm installation may also execute package lifecycle scripts under the invoking user's account.

The agent-browser install --with-deps command increases the installation scope by requesting browser and operating-system dependencies. Depending on the environment and package implementation, this step may require elevated privileges. The skill does not document a trusted publisher, reviewed version, registry restriction, checksum, signature, or reproducible dependency manifest.

This does not establish that the named packages are malicious. It creates a supply-chain weakness in which the software installed during a future invocation can differ from the software originally reviewed.

Attack Path

  1. An attacker compromises an upstream package, publisher account, registry resolution path, or transitive dependency.
  2. A malicious or compromised release becomes the version selected by the unpinned installation commands.
  3. A user follows the skill instructions and runs the global npm or ecosystem installation.
  4. Package lifecycle code or installed components execute with the user's privileges.
  5. If system dependency installation is authorized with elevated privileges, the compromise may extend to privileged files or system components.

Impact Assessment

Successful exploitation ...[truncated 461 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin every package to a reviewed, exact version instead of installing the latest release.
  • Document the expected publisher, official registry, package digest, and signature-verification procedure.
  • Use a project-local installation and a lockfile rather than a global npm installation where practical.
  • Disable package lifecycle scripts during installation unless they are required and have been reviewed.
  • Separate browser installation from operating-system dependency installation so elevated privileges are not granted to an opaque combined operation.
  • Review and pin transitive dependencies or use a verified artifact repository.
  • Add a verification step that compares downloaded artifacts against published cryptographic checksums.
  • Remove the optional ClawHub installation instruction unless the package source, version, and integrity controls are explicitly documented.

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:107
Finding

Authenticated Browser State Saved to an Unprotected Relative File

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:107-119
Additional Location: references/source-notes.md:18,32-33
Vulnerability Type: Insecure storage of sensitive authentication state
Risk Level: High

Vulnerable Code

markdown
### 4. Save auth state for recurring tasks

If the workflow requires login and will be reused:

```bash
agent-browser state save auth.json
agent-browser state load auth.json

This is often the difference between “semi-automated” and “truly one-command repeatable.”

text

The same storage pattern is repeated in `references/source-notes.md`:

```bash
agent-browser state save auth.json
agent-browser state load auth.json

Technical Analysis

The skill recommends persisting browser authentication state in auth.json, a predictable relative path, but does not require restrictive file permissions, encryption, a protected secrets directory, source-control exclusion, expiration controls, or secure deletion.

Browser state files commonly contain session cookies, local-storage values, or other bearer credentials. The exact contents depend on agent-browser and the target website, but any reusable session material must be treated as a secret. A relative filename may place the state in a project directory, shared working directory, backup set, or source-control workspace.

An attacker who can read and reuse valid session material may not need the user's password. The attacker could load the captured state into a compatible browser session and act with the privileges already granted to the authenticated account.

Attack Path

  1. A user authenticates to a target website through the browser automation workflow.
  2. The user runs agent-browser state save auth.json.
  3. The state file is created in the current directory without documented access restrictions or encryption.
  4. The file becomes accessible to another local user, a compromised process, a backu ...[truncated 993 chars]
Remediation
View remediation

Remediation Suggestions

  • Store browser state outside the project and current working directory in a dedicated secrets directory.
  • Create the directory and state file with owner-only permissions, such as 0700 for the directory and 0600 for the file on supported systems.
  • Use operating-system credential storage or encrypted secret storage rather than a plaintext JSON file where supported.
  • Use a unique, non-predictable state path for each target service and account.
  • Add all browser-state filenames and patterns to source-control ignore rules and secret-scanning policies.
  • Warn users that saved browser state may be equivalent to a password and must never be shared, logged, attached to support requests, or committed.
  • Avoid persistent state for financial, administrative, or otherwise high-impact services unless explicitly approved.
  • Define retention, expiration, revocation, rotation, and secure-deletion procedures.
  • Revoke target-site sessions immediately if a state file may have been disclosed.
  • Prefer short-lived, narrowly scoped sessions and target-site controls such as device binding or reauthentication for sensitive actions.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly instructs users to save and load browser authentication state to a local file (auth.json) but does not warn that this file may contain reusable session tokens, cookies, or other sensitive credentials. If that file is stored insecurely, shared, committed to source control, or reused across contexts, an attacker could hijack authenticated sessions without needing the original password.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 238)May include surrounding context.

md
Avoid these:

- using stale refs after navigation
- storing hardcoded assumptions without verification steps
- skipping auth-state management for recurring tasks
- claiming zero-token while still relying on repeated AI interpretation each run

Static analysis

No suspicious patterns detected.