Back to skill

Security audit

Auto Captcha Solver

Security checks for vulnerabilities and agentic risk

Overview

This skill does what it claims, but it can bypass CAPTCHA checks and submit protected forms automatically, so users should review it carefully before installing.

Install only for CAPTCHA flows you own or are explicitly authorized to test. Disable autoSubmit unless you intentionally want the form submitted, review any fallbackVision provider before use, and update/audit the image-processing dependencies before processing untrusted CAPTCHA images.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (15)

Tp4

High
Category
MCP Tool Poisoning
Confidence
89% confidence
Finding

The code is related to simple captcha OCR, so it partially aligns with the declared domain. However, the declared description presents a broader browser-automation skill that can capture captchas during flows, optionally compute arithmetic answers, fill form fields, and submit results. This code does not do those things. Instead, it is a narrow local OCR experiment/script for one image file, focused on preprocessing variants and ranking OCR outputs. It also includes behavior not implied by the description, namely checking for a specific expected answer string. Therefore the description overstates the implemented functionality and the actual code chunk materially differs in primary usage and capabilities.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The code is related to simple text captcha OCR, so it partially aligns with the declared domain. However, the declared description presents a broader browser-automation skill that captures captchas during flows, solves them, optionally computes arithmetic captchas, and fills/submits solutions. The supplied code does not perform those workflow actions. Instead, it is an offline OCR tuning/brute-force script operating on a single hardcoded local image, trying multiple image preprocessing variants and Tesseract engine/page-segmentation settings, then printing ranked OCR candidates. That is a materially narrower and different behavior than the declared end-to-end automation skill, so this should be flagged as a mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The code only implements one subpart of the declared skill: OCR-based solving of a local simple image captcha via preprocessing and Tesseract. It does not interact with Playwright, Puppeteer, or Selenium; does not capture captcha images from live browser flows; does not enter answers into forms or submit them; and does not implement arithmetic evaluation. The primary behavior is a standalone offline OCR/brute-force candidate generator for a hardcoded image path, which is materially narrower and operationally different from the declared end-to-end browser automation skill.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
89% confidence
Finding

The implemented code substantially matches the core claim of solving simple image captchas via preprocessing, OCR, arithmetic evaluation, and unsupported-type filtering. However, the declared description also claims browser-automation handling features such as capture, input fill, and submit handling across Playwright/Puppeteer/Selenium. None of those browser interaction capabilities are present in this code chunk; it only solves a provided image buffer and manages cache/calibration. This is a description-to-behavior mismatch because the declared operational scope is broader than the actual code behavior in a material way.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: sharp==0.34.5 — 2 advisory(ies): GHSA-f88m-g3jw-g9cj (sharp inherited vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, CVE-); GHSA-rgj7-g3m4-5g8c (sharp: Vulnerabilities in libheif: GHSA-g89c-p67h-r497 and GHSA-2jg2-4ch7-h545)

High
Category
Supply Chain
Confidence
92% confidence
Finding

The lockfile pins sharp to 0.34.5, and the static finding cites known advisories affecting sharp through bundled/native image-processing components such as libvips/libheif. Because this skill processes attacker-controlled captcha images, a vulnerable image decoder materially increases risk: crafted images could trigger memory corruption, denial of service, or potentially native-code execution in the host process depending on the vulnerable codec path.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: sharp==0.34.5 — 2 advisory(ies): GHSA-f88m-g3jw-g9cj (sharp inherited vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, CVE-); GHSA-rgj7-g3m4-5g8c (sharp: Vulnerabilities in libheif: GHSA-g89c-p67h-r497 and GHSA-2jg2-4ch7-h545)

High
Category
Supply Chain
Confidence
97% confidence
Finding

The dependency resolution indicates installation of sharp 0.34.5, which is associated with known vulnerabilities in bundled or inherited image-processing libraries such as libvips/libheif. Because this skill processes attacker-controlled captcha images, a vulnerable image parser materially increases the risk of crashes, denial of service, or potentially worse memory-corruption-style exploitation in environments running the automation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README explicitly promotes automatic CAPTCHA solving in browser automation, which facilitates bypass of an access-control and abuse-prevention mechanism commonly used by third-party services. Even without exploit code in the README itself, documenting this capability without clear authorization, legal, and safety boundaries increases the likelihood of misuse in credential stuffing, bulk account creation, or other abusive automation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documented autoSubmit: true flow enables the tool to not only solve a CAPTCHA but also immediately submit the protected form, reducing friction for unauthorized automated actions. In context, this makes the skill more operationally dangerous because it streamlines end-to-end abuse against login, registration, or transaction workflows with minimal human review.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The code submits the form automatically by clicking a submit element or sending Enter once a CAPTCHA is solved. There is no visible confirmation prompt, logging, or user-facing disclosure in this file that the skill may trigger a form submission, which can have side effects such as sending data or completing transactions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The setVerified method persists data to .captcha-verified.json using fs.writeFileSync, but there is no confirmation prompt, log message, comment, or docstring disclosing that the skill writes verification data to disk. For a code file, silent file writes that affect local data should be surfaced to the user unless clearly disclosed elsewhere.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This manifest file describes the skill as 'Automatically detect and solve simple captchas during browser automation' but does not specify when it should activate, what counts as a supported captcha, or any boundaries preventing broad invocation. In a manifest context, this lack of trigger specificity can cause unintended activation across general browser-automation tasks.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The code only blocks unsupported CAPTCHA types when caller-supplied hints contain markers like reCAPTCHA or hCaptcha. If hints are missing, incomplete, or wrong, the fallbackVision hook can still be invoked on unsupported challenges, enabling external solving behavior that contradicts the stated restriction and may facilitate bypass of stronger anti-bot mechanisms. In a browser automation skill specifically built to solve CAPTCHAs, this gap is more dangerous because it can be used in the exact context the manifest says must be avoided.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The code reads a local file from an absolute path, which is a file-access operation covered by the warning requirement for code files. There is no confirmation prompt, user-facing log, or explanatory comment/docstring indicating that the script will access this image file.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
92% confidence
Finding

Using a caret range for sharp allows future compatible releases to be installed automatically, which can introduce unexpected behavior or newly disclosed vulnerable versions into downstream environments. In security-sensitive automation tooling, dependency drift increases supply-chain risk and makes builds less reproducible.

Content

Scanner excerpt · package.json (reported line 22)May include surrounding context.

json
],
  "license": "MIT",
  "dependencies": {
    "sharp": "^0.34.1",
    "tesseract.js": "^6.0.1"
  }
}

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
90% confidence
Finding

Using a caret range for tesseract.js permits unreviewed updates within the semver range, increasing the chance of supply-chain compromise or accidental adoption of a problematic release. Reproducibility is especially important for browser automation skills that may run in privileged environments.

Content

Scanner excerpt · package.json (reported line 23)May include surrounding context.

json
"license": "MIT",
  "dependencies": {
    "sharp": "^0.34.1",
    "tesseract.js": "^6.0.1"
  }
}

Static analysis

No suspicious patterns detected.