Back to skill

Security audit

browser-automation

Security checks for vulnerabilities and agentic risk

Overview

This browser automation skill has no backdoor-like behavior, but it includes built-in stealth and anti-detection guidance that can help bypass website bot controls.

Install only if you intentionally want a browser automation skill that includes stealth and anti-detection techniques. Review generated scripts before running them, avoid using it to bypass site policies or anti-bot controls, and treat saved Playwright storage state files as secrets because they may contain active login sessions.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (30)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill is presented as ordinary browser automation, but it also includes static auditing, detection-risk scoring, stealth hardening recommendations, and CLI-style file/report workflows that materially expand its behavior. This mismatch increases the chance that a caller or orchestrator will invoke the skill in contexts where these additional capabilities are unexpected, reducing transparency and policy control.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

This document provides detailed guidance for evading bot detection, masking automation fingerprints, and making scripted browsing appear human. In the context of a general browser-automation skill, these techniques materially enable stealth scraping and access-pattern concealment beyond ordinary automation needs, increasing the risk of abuse against site defenses and terms-of-service controls.

Content

No source excerpt is available for this finding.

Context Leakage

High
Category
Data Exfiltration
Confidence
75% confidence
Finding

Code or instructions that leak agent conversation context to external services, potentially exposing sensitive user interactions.

Content

Scanner excerpt · references/data_extraction_recipes.md (reported line 419)May include surrounding context.

python
async def extract_threaded_comments(page, parent_selector=".comments"):
    """Recursively extract threaded comments."""
    return await page.evaluate(f"""
        (parentSelector) => {{
            function extractThread(container) {{

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This file is not a neutral quality checker; it explicitly audits Playwright scripts for 'bot detection vectors' and recommends countermeasures such as stealth hardening, fingerprint spoofing, randomized delays, and session persistence. In the context of a browser-automation skill, that materially enables users to evade website bot defenses and abuse scraping or form automation against targets that rely on those controls.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The module docstring explicitly lists anti-bot evasion dimensions such as navigator.webdriver, navigator property overrides, human-like delays, proxies, and session handling. That is direct natural-language guidance for bypassing detection controls, which is dangerous because it lowers the barrier to stealthy scraping, credential abuse, or automated fraud.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The generated report provides concrete stealth instructions, including removing navigator.webdriver and rotating user agents, which are common anti-bot evasion techniques. Turning those into actionable fixes makes the script a how-to guide for bypassing detection rather than a neutral auditor.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill describes capabilities that imply access to environment variables, filesystem reads/writes, and shell execution, but it does not declare an explicit tool scope or permissions boundary. That creates ambiguity about what the skill is allowed to do and can lead to overbroad execution in agents that infer capabilities from content rather than enforce least privilege.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The anti-detection section provides concrete guidance for removing WebDriver indicators, rotating realistic user agents, simulating human behavior, and using proxies to avoid bot detection. In a browser automation skill, this materially increases misuse potential by helping operators evade website defenses rather than merely automate legitimate browsing.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill includes stealth and anti-detection advice without warning about legal, contractual, or policy implications such as violating terms of service or circumventing access controls. That omission can normalize risky operator behavior and makes harmful use more likely in practice.

Content

No source excerpt is available for this finding.

Ssd 4

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The narrative explicitly promotes a progressive stealth stack for evading website safeguards during scraping, including navigator hardening, fingerprint evasion, behavioral simulation, and proxy rotation. This goes beyond reliability engineering and crosses into bypass guidance, which is dangerous because it can facilitate unauthorized scraping and circumvention of protective controls.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 238)May include surrounding context.

md
**Good:** Wrap each page interaction in try/except. Take error-state screenshots. Implement retry with exponential backoff.

### Ignoring robots.txt
**Bad:** Scraping without checking robots.txt directives.
**Good:** Fetch and parse robots.txt before scraping. Respect `Crawl-delay`. Skip disallowed paths. Add your bot name to User-Agent if running at scale.

### Storing Credentials in Scripts

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file presents anti-detection and fingerprint-evasion methods as recommended practice without any warnings about legal, policy, privacy, or abuse implications. That omission normalizes stealth techniques and lowers friction for misuse, especially when paired with concrete code snippets for detection avoidance.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The proxy rotation section explicitly supports repeated scraping while reducing detection and origin-based blocking. In a non-testing browser automation skill, that capability can be used to bypass rate limits, IP reputation controls, and abuse-prevention mechanisms, making otherwise detectable automation harder to contain.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Saving Playwright storage state to disk can persist cookies, localStorage, and active authentication artifacts in a reusable file. Without an explicit warning, users may unknowingly create credential-bearing files that can be copied, committed, or reused to hijack authenticated sessions.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The reference includes explicit anti-detection and stealth techniques such as masking navigator.webdriver, spoofing plugins, and overriding languages. In a general browser automation skill, these instructions can facilitate evasion of bot detection and abuse of third-party services, and they are not necessary for ordinary scraping, form filling, or screenshot workflows.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Forcing browser languages inside the stealth section is part of an anti-detection evasion pattern rather than a neutral localization example. In context, it helps disguise automated activity and may reduce transparency about the true execution environment, increasing abuse potential.

Content

No source excerpt is available for this finding.

Ssd 4

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The tool narrative walks users through a layered anti-detection model—headless mode, fingerprints, timing, sessions, proxies, and stealth libraries—creating a progressive roadmap for evasion. Even without exploit code execution, this kind of embedded coaching increases misuse potential in a broadly scoped automation skill.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The class is presented as analyzing 'bot detection vulnerabilities,' but its checks are oriented toward improving stealth rather than identifying security weaknesses in the user's own code. That framing can normalize or conceal misuse by making anti-detection evasion appear like routine engineering hygiene inside a general browser-automation skill.

Content

No source excerpt is available for this finding.

Ssd 2

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Across the recommendations and output formatting, the script advises human-mimicking delays, fingerprint hardening, proxy use, and persistent sessions to avoid security alerts. These are classic stealth-enablement patterns that, in a browser-automation context, meaningfully increase the capability to evade bot detection at scale.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The generated script includes a pool of realistic browser user agents and randomly selects one for each run, which adds evasion capability beyond the stated purpose of filling forms. While not inherently malicious alone, this helps disguise automation characteristics and can facilitate scraping or policy circumvention on websites.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The generated script deliberately modifies browser-exposed properties to hide Playwright/WebDriver automation by setting navigator.webdriver to undefined. This is stealth behavior unrelated to basic form automation and can enable evasion of bot-detection controls on third-party sites, increasing misuse risk in a browser-automation skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script silently performs stealth browser modification without any warning, disclosure, or user opt-in, specifically masking the webdriver signal that sites use to identify automation. In the context of a browser-automation skill, this makes the capability more dangerous because it operationalizes covert interaction with external websites rather than transparent automation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This generator intentionally emits anti-detection settings such as random delays, user-agent rotation, and later webdriver-evasion behavior in the produced Playwright script. In a browser-automation/scraping skill, that crosses from ordinary automation into stealthy scraping behavior that can facilitate abuse of third-party sites and make operator actions harder to detect or attribute.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The generated script injects code to hide navigator.webdriver, which is a classic browser automation evasion technique. Including this by default without prominent disclosure makes the skill materially more dangerous because it helps generated automation bypass bot-detection controls on target websites.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The tool writes attacker-influenced generated content directly to an arbitrary user-specified path and marks non-JSON output executable without overwrite safeguards, prompts, or path restrictions. This can clobber existing files or create a runnable script unexpectedly, increasing the risk of unsafe file replacement in automation contexts.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.