Back to skill

Security audit

Agent Browser Clawdbot 0.1.0

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent browser automation helper, but it needs review because it handles browser session data and installs a broad mutable dependency without enough scoping or secret-handling guidance.

Review this before installing. Use it only in a trusted workspace, prefer a pinned local install or sandbox, avoid administrative installs unless necessary, and treat saved browser state, cookies, and localStorage like credentials. Do not commit or share auth state files, keep them outside repositories, restrict file permissions, and delete them when no longer needed.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Error
Location
SKILL.md:194
Finding

Unpinned Global Installation of Third-Party Browser Automation Dependencies

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 194-199
Vulnerability Type: Unverified and mutable third-party dependency installation
Risk Level: High

Vulnerable Code Snippet:

markdown
## Installation

```bash
npm install -g agent-browser
agent-browser install                     # Download Chromium
agent-browser install --with-deps         # Linux: + system deps
text

### Technical Analysis

The installation instructions globally install `agent-browser` without specifying a reviewed version, integrity digest, lockfile, signature, or other artifact-verification mechanism. The subsequently installed CLI is also instructed to download Chromium and, when `--with-deps` is used, install additional system dependencies.

Because the package reference is mutable, the code installed when a user follows these instructions may differ from the code that existed when the Skill was audited. Linking to a GitHub homepage elsewhere in the document does not cryptographically verify that the package retrieved from the npm registry corresponds to the reviewed repository or commit.

Global installation increases the affected scope compared with a project-local dependency. Depending on the operating environment and how system dependencies are installed, the `--with-deps` operation may also request or use elevated system permissions.

### Attack Path

1. An attacker compromises the dependency publisher, npm account, registry distribution channel, or a downstream installation component.
2. The attacker publishes or substitutes a malicious version under the expected package name.
3. A user follows the Skill instructions and runs `npm install -g agent-browser` without a pinned version or integrity validation.
4. The mutable package is installed globally and its installation hooks or executable code run with the invoking user's permissions.
5. The installed CLI may then access local files, browser sessions, auth
...[truncated 582 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin agent-browser to an explicitly reviewed version rather than installing the latest mutable release.
  2. Record and verify the expected package integrity digest or signature before installation.
  3. Document the trusted npm registry, expected publisher identity, source repository, and reviewed source commit.
  4. Prefer a project-local installation with a committed lockfile over a global installation.
  5. Disable or separately review package lifecycle scripts where operationally possible.
  6. Pin and verify the Chromium release downloaded by the CLI.
  7. Review system dependencies separately and avoid --with-deps unless required.
  8. Perform installation under a non-administrative account or in a sandboxed container with minimal filesystem and network access.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:106
Finding

Authentication State Persisted Without Secure Storage Guidance

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 106 and line 161
Vulnerability Type: Insecure storage of sensitive browser authentication material
Risk Level: Medium

Vulnerable Code Snippets:

bash
agent-browser state save auth.json        # Save cookies/storage
markdown
4. **Save auth state** - Skip login flows with `state save/load`

Technical Analysis

The Skill recommends saving browser state to a plainly named local file, auth.json, and promotes state persistence as a best practice. Browser state may contain session cookies, bearer tokens, local-storage credentials, or other data sufficient to resume an authenticated session.

The instructions do not require restrictive file permissions, encryption, an isolated secrets directory, source-control exclusion, retention limits, or secure deletion. If the command is run from a shared or repository-backed working directory, the resulting file may be readable by other local processes, included in backups or build artifacts, or accidentally committed to version control.

Attack Path

  1. The agent authenticates to a website and establishes a privileged browser session.
  2. The user or agent follows the documented instruction and saves the browser state as auth.json.
  3. The file remains in the working directory without documented access restrictions or encryption.
  4. Another local user or process reads the file, or it is exposed through a repository commit, backup, artifact upload, or log collection process.
  5. An attacker imports or extracts the saved cookies and tokens.
  6. If the credentials remain valid and are not protected by additional server-side controls, the attacker replays the session and accesses the associated account.

Impact Assessment

Exposure of the state file may allow unauthorized access to the websites represented by its stored sessions. The attainable privileges are limited to those of the captured ...[truncated 292 chars]

Remediation
View remediation

Remediation Suggestions

  1. Do not persist authenticated browser state unless it is operationally necessary.
  2. Save state in a dedicated secrets directory outside repositories and ordinary working directories.
  3. Create state files with owner-only permissions and ensure parent directories are not accessible to other users.
  4. Encrypt saved state at rest using an operating-system credential store or managed secret-storage service.
  5. Add state filenames and patterns to .gitignore, backup exclusions, artifact exclusions, and log-redaction rules.
  6. Use separate state files for different users, roles, environments, and domains to limit exposure.
  7. Apply short retention periods and securely delete files immediately after use.
  8. Revoke affected sessions and rotate related credentials if a state file may have been exposed.
  9. Document that state files must never be uploaded, attached to reports, or shared between untrusted environments.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly recommends saving and reloading browser auth state but does not warn that these files can contain cookies, tokens, and other session material that grant account access. In an agent context, this increases the chance that sensitive state is written to disk, reused across tasks, or exfiltrated through logs, artifacts, or shared workspaces.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill exposes commands to read and modify cookies and localStorage without any guidance on handling sensitive data or respecting privacy boundaries. In an AI-agent workflow, these commands can easily surface session cookies, CSRF tokens, or user data into command output, logs, or downstream prompts, enabling credential theft or unintended disclosure.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.