Back to skill

Security audit

Browser Network Inspector

Security checks for vulnerabilities and agentic risk

Overview

This browser debugging skill is mostly coherent, but it can save sensitive browser network data to plaintext reports with weaker redaction than users are told to expect.

Install only if you are comfortable with local reports potentially containing tokens, cookies, passwords, personal data, or private API payloads. Use include-host filters, avoid sensitive login flows unless necessary, disable WebSocket capture when possible, and treat generated JSON/Markdown reports as sensitive files.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/collect-network.js:85
Finding

Incomplete Redaction Can Persist Authentication and Session Data in Plaintext

Content
View full analysis
` : redactValue(key, value); } return obj; } if (typeof body === 'object') return redactObject(body); return truncate(String(body)); } ``` `scripts/collect-network.js:142-153`: ```js const response = await originalFetch(input, init); const cloned = response.clone(); let responseText = null; try { responseText = await cloned.text(); } catch {} const parsed = tryParseJson(responseText); pushLog({ source: 'fetch', url, method, durationMs: Date.now() - startedAt, requestHeaders, requestBody, status: response.status, ok: response.ok, responseHeaders: normalizeHeaders(response.headers), responseBody: parsed ? redactObject(parsed) : truncate(responseText), }); ``` `scripts/collect-network.js:180-185`: ```js let responseBody = null; try { if (typeof this.responseText === 'string') { const parsed = tryParseJson(this.responseText); responseBody = parsed ? redactObject(parsed) : truncate(this.responseText); } } catch {} ``` `scripts/collect-network.js:204` and `scripts/collect-netwo ...[truncated 3890 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (10)

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

Although the description frames the skill as passive browser-side inspection, the documented workflow actively injects JavaScript into pages, drives an external browser-control binary, and includes helpers that modify session state. That mismatch is dangerous because operators or automated systems may approve the skill under a lower-risk mental model while it actually has active execution and state-manipulation capability.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 31)May include surrounding context.

md
- Extracting or replaying third-party login sessions
- Capturing full system traffic
- Pulling access tokens, cookies, session secrets, or passwords for reuse
- Bypassing captchas, auth, or platform protections

## About the capture model

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 115)May include surrounding context.

md
- `scripts/capture-and-report.js` — create a timestamped report directory and save both JSON + Markdown

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · scripts/collect-network.js (reported line 113)May include surrounding context.

js
function matchesHostRule(host, rules) {
    if (!rules || !rules.length) return false;
    return rules.some(rule => host === rule || host.endsWith(`.${rule}`));
  }

  function shouldCapture(url) {

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill invokes external browser tooling and accesses environment-specific paths, but it does not declare any tool scope or allowed-tools constraints. That creates an authorization gap where an agent may run code with broader-than-expected capabilities, making misuse or accidental overreach more likely.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
80% confidence
Finding

The script injects collector code into agent-browser, configures capture, and exports collected network data, but the only visible messaging is a final success log after files are saved. There is no user-facing warning in code comments, docstrings, or runtime output that the tool is actively collecting browser network activity, which may include sensitive hosts or request details.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

This code creates the output directory and writes captured browser network session data to a JSON file, which can contain sensitive request metadata. Although the script logs the saved path afterward, there is no prior user-facing warning, confirmation, or explanatory comment/docstring disclosing that session data will be persisted to disk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This code invokes an external executable to clear browser/session state, which is a potentially destructive operation affecting user data. Although the script prints a result afterward, there is no confirmation prompt, pre-action warning, or explanatory comment/docstring disclosing that session data will be cleared before the operation runs.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script installs page-wide hooks for fetch, XMLHttpRequest, and WebSocket, stores captured request and response metadata in a global in-memory log, and exposes export access via window.__bniExport without any built-in user-facing notice, consent check, or access control in this code. Even though the stated skill purpose is browser debugging and the code attempts redaction, it still captures broad network activity and some sensitive content may evade the heuristic redaction, making silent collection risky in shared or agent-driven browsing contexts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script includes requestBody and responseBody content from failed network events in the generated Markdown report, and can persist that report to disk when an output path is provided. Network logs commonly contain credentials, session tokens, personal data, or API secrets, so summarizing and storing these fields without redaction, opt-in disclosure, or sensitivity filtering creates a real confidentiality risk.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec, suspicious.dynamic_code_execution

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/capture-and-report.js:56

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/capture-session.js:50

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/clear-session.js:21

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
scripts/capture-session.js:79