Back to skill

Security audit

Agent Browser Core

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent browser-automation documentation skill with disclosed high-risk controls, though users should pin and isolate its install commands.

Install only in a dedicated non-root environment, pin exact trusted versions of agent-browser and Playwright, avoid global installs where possible, and require explicit approval before using file access, eval, credential/state mutation, proxies, or traffic interception.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
references/agent-browser-overview.md:8
Finding

Unpinned Third-Party Package Execution and Dynamic Runtime Downloads

Content
View full analysis

Vulnerability Details

File Location: references/agent-browser-overview.md:8-17; repeated installation guidance appears in references/agent-browser-troubleshooting.md:3-5
Vulnerability Type: Supply-chain risk from unpinned dependencies and dynamically downloaded components
Risk Level: Medium

Vulnerable Code Snippet:

markdown
## 2) Install and setup (hardened)
- Pin the version you trust:
  - `npm install -g agent-browser@<version>`
- Prefer a dedicated environment or container for installs.
- Avoid running with elevated OS privileges.
- Install browser runtime:
  - `agent-browser install`
- Linux dependencies (if needed):
  - `agent-browser install --with-deps`
  - or `npx playwright install-deps chromium`

The troubleshooting guide repeats commands that retrieve browser artifacts or system dependencies:

markdown
## CLI runs but no browser opens
- Run `agent-browser install` to download Chromium.
- On Linux, run `agent-browser install --with-deps` if dependencies are missing.

Technical Analysis

The documentation recommends pinning agent-browser, but supplies only the placeholder <version> rather than an audited exact version. It also invokes npx playwright without specifying a version. Depending on the local npm configuration and cache, npx may retrieve and execute a package from a remote registry at invocation time.

The agent-browser install, agent-browser install --with-deps, and playwright install-deps operations retrieve external artifacts or install host dependencies. No lockfile, integrity digest, verified download source, or trusted-registry configuration is provided. Consequently, the effective code and artifacts installed can differ from those reviewed with this Skill.

This is a supply-chain weakness rather than evidence that the current documentation or package contains an intentionally malicious payload. The project does include ...[truncated 1711 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace agent-browser@<version> with a reviewed, exact version rather than a range, tag, or placeholder.
  2. Pin Playwright explicitly, for example by using npm exec --package=playwright@<audited-exact-version> -- playwright install-deps chromium.
  3. Provide and enforce a lockfile for all Node.js dependencies and require lockfile-based installation where applicable.
  4. Verify package integrity using registry integrity metadata, trusted checksums, signatures, or provenance attestations.
  5. Explicitly configure the expected official package registry and reject unexpected registry overrides.
  6. Pin and verify downloaded browser-runtime artifacts where the tooling supports checksum or signature validation.
  7. Perform installation and browser automation in a disposable, non-root container or similarly isolated environment with minimal filesystem and network access.
  8. Avoid global installation when possible; prefer a project-local, locked dependency or an isolated tool environment.
  9. Separate browser-runtime installation from operating-system dependency installation, and require explicit human approval before any command that changes system packages.
  10. Document the exact trusted versions, artifact sources, hashes, and upgrade-review process so installation is reproducible.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

The documentation recommends npx playwright install-deps chromium, which invokes an unpinned package name and allows whatever Playwright version is currently resolved at execution time. In an agent/browser automation skill, this weakens supply-chain control and can lead to unexpected code execution or dependency drift if a compromised or incompatible package version is fetched.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.