Back to skill

Security audit

Browser Automation

Security checks across malware telemetry and agentic risk

Overview

This is a simple browser automation skill that clearly advertises web actions, scraping, uploads, and session reuse, with no hidden code or install-time behavior found.

Install only if you are comfortable letting your agent automate browsers on sites you choose. Before using session reuse, cookie saving, multi-account switching, scraping, or file upload, confirm the account, site, files, and data scope explicitly, and avoid using it to bypass site rules or access data you are not authorized to use.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill explicitly advertises file upload, structured data extraction, cookie save/load, login reuse, and multi-account switching, but its safety section only mentions robots.txt, rate control, and avoiding malicious use. That omits key privacy and credential-handling warnings, increasing the risk that users or downstream agents will automate collection of sensitive data, reuse authenticated sessions, or upload local files without clear consent boundaries.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.