Back to skill

Security audit

Web Automation Helper

Security checks for vulnerabilities and agentic risk

Overview

The skill is a browser automation helper, but it asks users to enable Chrome remote debugging without enough safety guidance for a powerful browser-control interface.

Review before installing. Use this only with a separate Chrome profile and trusted local environment, avoid using a daily logged-in browser profile, keep the debug port bound to localhost, and close the debugging session when finished. The current helper mostly verifies CDP connectivity rather than providing full automation.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description promises a browser automation assistant capable of executing web operations through Chrome remote debugging. However, the supplied code only fetches the Chrome DevTools WebSocket debugger URL from http://localhost:9222/json/version and prints status information. It does not open pages, control the browser, scrape content, fill forms, publish content, or capture screenshots. While the code is related to Chrome remote debugging, its actual behavior is only a minimal connectivity/helper check, which is materially narrower than the declared purpose.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README instructs users to launch Chrome with a remote debugging port but does not warn that this interface can expose full browser control to other local or network-accessible processes. In the context of a browser automation skill, that omission increases the chance that users will run an unsafe configuration and unintentionally expose cookies, session data, or authenticated browser actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documentation instructs users to launch Chrome with remote debugging enabled but does not warn that DevTools access can control browser state, inspect page contents, and interact with authenticated sessions. In the context of browser automation, this omission can lead users to expose sensitive data or accounts without understanding the security implications.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The README presents all user-facing instructions exclusively in Chinese, which can constitute a language policy violation when the skill forces a specific language without offering user choice. There is no note that the skill is region-specific or that another language option is available.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description and headings are presented in Chinese, with no indication that another language is supported or that the locale restriction is intentional. Per the policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The natural-language fields in the manifest are written entirely in Chinese, including the description and feature list, with no indication that the skill is region-specific or that users can opt into another language. Under the stated policy, forcing a specific language without user opt-in can be a locale-policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.