Back to skill

Security audit

Grok Browser

Security checks for vulnerabilities and agentic risk

Overview

This skill does what it says, but it asks an agent to control a real Chrome/Grok session using unsafe JavaScript templates and the global clipboard.

Install only if you are comfortable letting the agent drive your Chrome Grok session. Use a dedicated browser profile with no unrelated tabs or sensitive accounts, avoid untrusted prompt text unless it is safely serialized before evaluate, and treat clipboard reads as potentially exposing whatever was already copied.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:37
Finding

Unescaped Query Interpolation Enables JavaScript Injection

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 37; the same unsafe pattern is repeated at lines 69 and 173
Vulnerability Type: JavaScript injection through unescaped query interpolation
Risk Level: Medium

Vulnerable Code:

javascript
"fn": "(() => { const editor = document.querySelector('[contenteditable=\"true\"]'); if(editor) { editor.focus(); editor.innerText = 'YOUR_QUERY_HERE'; return 'typed'; } return 'not found'; })()"

Related examples repeat the same construction:

javascript
"fn": "(() => { const e = document.querySelector('[contenteditable=\"true\"]'); if(e) { e.focus(); e.innerText = 'What is quantum computing?'; return 'ok'; } return 'fail'; })()"
javascript
"fn":"(() => { const e = document.querySelector('[contenteditable=\"true\"]'); e.focus(); e.innerText = 'Explain quantum entanglement briefly'; return 'ok'; })()"

Technical Analysis

The skill tells an agent to replace YOUR_QUERY_HERE with query content inside a single-quoted JavaScript string and then execute the generated source through the browser's evaluate operation. It does not require the query to be escaped or serialized first.

If attacker-controlled query text contains a single quote followed by valid JavaScript syntax, it can terminate the intended string literal and introduce additional statements. Because the resulting source is passed to evaluate, those statements execute in the context of the currently authenticated Grok page rather than being treated exclusively as text.

Assigning data to innerText is ordinarily safe, but that protection does not apply here because the untrusted value is first interpolated into executable JavaScript source. The injection occurs before the innerText assignment is evaluated.

Attack Path

  1. An attacker supplies or influences a query that contains a string terminator and additional JavaScript syntax.
  2. An agent follows the documented work ...[truncated 1583 chars]
Remediation
View remediation

Remediation Suggestions

Do not concatenate query content into JavaScript source. Apply the following hardening measures:

  1. Prefer a browser automation typing or fill operation that accepts the query as data and does not evaluate generated JavaScript.
  2. If evaluate is unavoidable, pass the query as a separately serialized argument supported by the browser automation interface.
  3. Where argument passing is unavailable, serialize the complete query with a trusted JSON serializer such as JSON.stringify before incorporating it into the expression. Do not perform manual quote replacement.
  4. Update every occurrence of this pattern, including lines 37, 69, and 173.
  5. Document that raw user input must never be substituted into executable source templates.
  6. Add tests using quotes, backslashes, line separators, template delimiters, and attempted statement injection to verify that all supplied content remains inert text.
  7. Use a dedicated, least-privileged browser profile without unrelated authenticated tabs or sensitive session data to reduce impact if browser automation is compromised.

A safer conceptual implementation passes the query as data:

javascript
(query) => {
  const editor = document.querySelector('[contenteditable="true"]');
  if (!editor) return 'not found';
  editor.focus();
  editor.innerText = query;
  return 'typed';
}

The automation API should supply query as an argument rather than embedding it into the function's source code.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill requires executing local shell commands and a user-specific relay script from an absolute path, which exceeds the narrow manifest description of querying Grok via browser automation. This creates unnecessary access to local execution capabilities and trusts an opaque local script whose behavior is not described, increasing the risk of unintended command execution or environment-specific abuse.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill instructs reading the system clipboard with pbpaste, which accesses global clipboard contents rather than a skill-scoped buffer. Even if intended to retrieve Grok's copied response, this can expose unrelated sensitive data if the clipboard was changed or already contained secrets, and the skill provides no validation or warning about that broader access.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The workflow tells users to copy responses to the system clipboard and read them back without any warning that clipboard contents are globally accessible to other apps and may overwrite or expose unrelated data. In this context the issue is primarily an information-handling weakness rather than direct code execution, but it still increases the chance of accidental data disclosure.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.