Back to skill

Security audit

Agent Browser

Security checks for vulnerabilities and agentic risk

Overview

This browser automation skill is purpose-aligned, but it needs Review because it can reuse logged-in browser sessions, run page scripts, access clipboard data, and persist authentication state with mostly opt-in safeguards.

Install only if you trust the agent-browser package source and are comfortable giving an agent broad browser-control authority. Prefer a dedicated browser profile, enable domain allowlists and action policy before authenticated work, avoid auto-connecting to your daily Chrome profile, treat saved state files as credentials, keep recordings/screenshots/traces out of shared logs or repos, and pin or locally vet executable dependencies where possible.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:9
Finding

Unpinned Global Installation of Executable Dependencies

Content
View full analysis
Remediation
View remediation

other

Warning
Location
references/authentication.md:23
Finding

Overbroad Collection of Authenticated Browser State Through Chrome Debugging

Content
View full analysis
`--remote-debugging-port` exposes full browser control on localhost. Any local process can connect and read cookies, execute JS, etc. ### Technical Analysis Chrome DevTools Protocol access is a high-privilege browser capability. A process connected to the debugging endpoint can inspect browser content, execute JavaScript, and access authentication material available to the connected browser context. The documented `--auto-connect` workflow discovers a running Chrome instance and exports cookies and localStorage into a state file. This can expose substantially more authenticated browser state than is necessary for a single target-site workflow, particularly when a normal multi-purpose browser profile is used. The documentation acknowledges part of this risk, but the primary workflow still recommends broad auto-discovery and state export. It does not enforce a dedicated profile, restrict exported state to a validated origin, authenticate the debugging connection, or require confirmation of the selected browser instance. No external ex ...[truncated 1227 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
templates/authenticated-session.sh:28
Finding

Authentication Tokens Persisted in a Plaintext Project-Local State File

Content
View full analysis
[state-file]}" STATE_FILE="${2:-./auth-state.json}" echo "Authentication workflow: $LOGIN_URL" if [[ -f "$STATE_FILE" ]]; then echo "Loading saved state from $STATE_FILE..." if agent-browser --state "$STATE_FILE" open "$LOGIN_URL" 2>/dev/null; then agent-browser wait --load networkidle CURRENT_URL=$(agent-browser get url) if [[ "$CURRENT_URL" != *"login"* ]] && [[ "$CURRENT_URL" != *"signin"* ]]; then echo "Session restored successfully" agent-browser snapshot -i exit 0 fi echo "Session expired, performing fresh login..." agent-browser close 2>/dev/null || true else echo "Failed to load state, re-authenticating..." fi rm -f "$STATE_FILE" fi ``` From the customizable login flow at `templates/authenticated-session.sh:101-102`: ```bash # echo "Saving state to $STATE_FILE" # agent-browser state save "$STATE_FILE" ``` The documented state contents in `references/session-management.md:62-68` are: ```json { "cookies": [...], "localStorage": {...}, "sessionStorage": {...}, "origins": [...] } ``` ### Technical Analysis The authentication template defaults to `./auth-state.json`, a file inside the current project directory. Once the documented login section is enabled, cookies, localStorage, sessionStorage, and origin data can be saved there. These values commonly include bearer tokens or session identifiers that provide access without requiring the user's password. Although the surrounding documentation recommends encryption, dele ...[truncated 1830 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (25)

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The trigger text is extremely broad and includes generic website-related requests plus catch-all browser automation language, making accidental or overly eager activation likely. Because this skill has powerful capabilities including authentication reuse, downloads, state persistence, and code execution in page context, overbroad activation materially increases the chance of unsafe tool use on untrusted content.

Content

No source excerpt is available for this finding.

Context Leakage

High
Category
Data Exfiltration
Confidence
85% confidence
Finding

Session recording and DevTools inspection can capture page contents, credentials, tokens, and other sensitive contextual information that may persist to disk or be exposed beyond the immediate task. In a browser automation skill that is frequently used on authenticated sites, this increases the risk of context leakage and retention of private data.

Content

Scanner excerpt · SKILL.md (reported line 326)May include surrounding context.

agent-browser --headed open https://example.com agent-browser highlight @e1 # Highlight element agent-browser inspect # Open Chrome DevTools for the active page agent-browser record start demo.webm # Record session agent-browser profiler start # Start Chrome DevTools profiling agent-browser profiler stop trace.json # Stop and save profile (path optional)

text

YARA rule 'info_stealer': Information stealer patterns (credential harvesting, browser data theft) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · references/authentication.md (reported line 24)May include surrounding context.

ication](#restoring-authentication)

Import Auth from Your Browser

The fastest way to authenticate is to reuse cookies from a Chrome session you are already logged into.

Step 1: Start Chrome with remote debugging

bash
# macOS
"/Applications/Google Chrome.app/Contents/MacOS/Google Chrome" --remote-debugging-port=9222

# Linux
google-chrome --remote-debugging-port=9222

# Windows
"C:\Program Files\Google\Chrome\Application\chrome.exe" --remote-debugging-port=9222

Log in to your target site(s) in this Chrome window as you normally would.

Security note: --remote-debugging-port exposes full browser control on localhost. Any local process can connect and read cookies, execute JS, etc.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/authentication.md (reported line 294)May include surrounding context.

  1. Clean up after automation

    bash
    agent-browser cookies clear
    rm -f ./auth-state.json
    
  2. Use short-lived sessions for CI/CD

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/session-management.md (reported line 185)May include surrounding context.

echo "*.auth-state.json" >> .gitignore

Delete after use

rm /tmp/auth-state.json

text

### 4. Timeout Long Sessions

Rp1

Medium
Category
MCP Rug Pull
Confidence
84% confidence
Finding

The skill metadata references npx agent-browser without version pinning, so tool execution may resolve to an unreviewed package release at runtime. That expands the trust boundary from the reviewed skill content to the live npm ecosystem and makes compromise or drift materially more dangerous.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

The manifest allowlists execution of npx agent-browser:* without pinning a specific package version, which permits whatever version is currently published or resolved at runtime to be fetched and executed. In an agent setting, that creates a supply-chain risk where a compromised upstream package or unexpected major-version change could execute arbitrary code with the agent's privileges.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The skill documents credential storage, plaintext session-state files, auto-connection to an already logged-in browser, downloads, screenshots, recording, and clipboard access, but does not foreground privacy and data-handling risks before those features are introduced. In an agent environment, that omission can cause operators or downstream models to invoke sensitive actions without understanding that secrets, tokens, local files, and user activity may be captured or persisted.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Clipboard read/write operations allow the skill to access or overwrite data outside the immediate browser page workflow, including secrets a user copied from other applications. For an agent, that broadens data access beyond the stated browser automation purpose and creates a path for exfiltration, credential capture, or destructive overwrites of user clipboard contents.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The documented eval capability enables arbitrary JavaScript execution in the browser context, which is broader than simple navigation and form interaction. In an agent workflow, this can be used to extract sensitive page data, manipulate application state, bypass intended guardrails, or relay untrusted page content back into the model context in more dangerous forms.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
69% confidence
Finding

The configuration encourages persistent local profiles and saved settings, which can retain cookies, session tokens, browsing artifacts, and potentially proxy/auth configuration across runs. In a multi-task or multi-user agent environment, that persistence increases the chance of unintended session reuse, cross-task data leakage, and stale privileged state being silently applied.

Content

Scanner excerpt · SKILL.md (reported line 574)May include surrounding context.

Configuration File

Create agent-browser.json in the project root for persistent settings:

json
{

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The basic login example shows a literal password value in a command, which normalizes unsafe credential handling and makes it easy for users to copy hardcoded secrets into shell history, docs, or scripts. In an agent/browser-automation skill, this is more dangerous because the documentation directly teaches operational auth workflows, so insecure examples are likely to be reused in real environments.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The OAuth example instructs direct entry of email and password during an SSO flow without an adjacent warning about handling IdP credentials safely. This can encourage users to script sensitive account credentials into automation, increasing risk of credential leakage through logs, transcripts, command history, and shared example code.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
80% confidence
Finding

Network request inspection, custom headers, and credential-setting capabilities can reveal or transmit sensitive data such as authorization headers, cookies, or basic-auth credentials, yet the documentation gives no privacy or handling warning. In browser automation, this can facilitate inadvertent collection or disclosure of secrets during debugging, scraping, or test execution.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The cookie and storage commands expose direct read/write access to browser cookies and localStorage but provide no warning that these often contain session identifiers, CSRF tokens, or personal data. In an agent context, that omission increases the risk of accidental disclosure, unsafe logging, or destructive clearing of important browser state.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The documented eval functionality explicitly supports arbitrary JavaScript execution in the page context, including unrestricted scripts via base64 or stdin. In a browser-automation skill, this materially expands capability from UI interaction into code execution inside arbitrary web origins, enabling extraction of page data, access to DOM-visible secrets, and actions that bypass safer higher-level command constraints.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The state save/load commands are documented as persisting cookies, storage, and auth state without warning that the output file may contain session tokens and other sensitive authentication artifacts. This can lead agents or users to persist reusable credentials insecurely, making account takeover or unauthorized session reuse possible if the file is exposed.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
84% confidence
Finding

Restoring saved browser state enables reuse of prior authenticated sessions, which is inherently sensitive because the state file may act as a portable login token. In this skill, session persistence is more dangerous because the tool is designed for autonomous browser actions, so loading compromised state can silently grant broad account access across sites.

Content

Scanner excerpt · references/commands.md (reported line 216)May include surrounding context.

bash
agent-browser state save auth.json    # Save cookies, storage, auth state
agent-browser state load auth.json    # Restore saved state

Global Options

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation describes capturing and saving Chrome performance traces but never warns that trace files can include sensitive telemetry such as visited URLs, timing of user interactions, JavaScript execution details, network-related metadata, and application-specific user timing marks. In an agent-driven browser automation context, those traces may be generated while logged into real services or interacting with user data, increasing the chance that operators store, share, or upload sensitive artifacts without realizing the exposure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documentation recommends embedding proxy credentials directly in the HTTP_PROXY URL without warning that environment variables and shell history can leak secrets to process listings, logs, crash reports, or child processes. In an agent/browser automation context, operators may copy this pattern into scripts and CI environments, increasing the chance of credential exposure and unauthorized proxy use.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The SOCKS5 authenticated proxy example also embeds credentials in ALL_PROXY and does not warn about secret handling risks. This can lead users to expose usernames and passwords through shell history, environment inspection, support bundles, or inherited process environments, which is especially relevant for an automation skill likely to run in shared developer or CI systems.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
55% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/session-management.md (reported line 55)May include surrounding context.

Load Session State

bash
# Restore saved state
agent-browser state load /path/to/auth-state.json

# Continue with authenticated session

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation encourages recording browser sessions for login workflows, debugging, and CI artifacts but does not warn that videos can capture credentials, session state, PII, internal URLs, or other sensitive on-screen data. In an agent-browser skill, this is more dangerous because agents may automate authenticated sessions and store artifacts automatically, increasing the chance of sensitive recordings being retained, shared, or uploaded to logs and build systems.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This workflow captures full-page screenshots, text, structure, and PDFs and saves them to local disk without any warning, minimization, or confirmation step around sensitive content. In a browser automation skill, this is meaningfully risky because pages may contain personal data, credentials, internal documents, or regulated information that gets persistently stored and later exposed through logs, backups, or shared workspaces.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The template documents loading a stored authentication state for protected pages without warning about the sensitivity of reusing authenticated sessions. That can cause the tool to capture privileged content under a user's session and save it locally, increasing the chance of unauthorized disclosure of account data, internal resources, or other protected material.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.