T08 · Insecure Dependencies
- Location
SKILL.md:9- Finding
Unpinned Global Installation of Executable Dependencies
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This browser automation skill is purpose-aligned, but it needs Review because it can reuse logged-in browser sessions, run page scripts, access clipboard data, and persist authentication state with mostly opt-in safeguards.
Install only if you trust the agent-browser package source and are comfortable giving an agent broad browser-control authority. Prefer a dedicated browser profile, enable domain allowlists and action policy before authenticated work, avoid auto-connecting to your daily Chrome profile, treat saved state files as credentials, keep recordings/screenshots/traces out of shared logs or repos, and pin or locally vet executable dependencies where possible.
SKILL.md:9Unpinned Global Installation of Executable Dependencies
references/authentication.md:23Overbroad Collection of Authenticated Browser State Through Chrome Debugging
templates/authenticated-session.sh:28Authentication Tokens Persisted in a Plaintext Project-Local State File
The trigger text is extremely broad and includes generic website-related requests plus catch-all browser automation language, making accidental or overly eager activation likely. Because this skill has powerful capabilities including authentication reuse, downloads, state persistence, and code execution in page context, overbroad activation materially increases the chance of unsafe tool use on untrusted content.
Session recording and DevTools inspection can capture page contents, credentials, tokens, and other sensitive contextual information that may persist to disk or be exposed beyond the immediate task. In a browser automation skill that is frequently used on authenticated sites, this increases the risk of context leakage and retention of private data.
agent-browser --headed open https://example.com agent-browser highlight @e1 # Highlight element agent-browser inspect # Open Chrome DevTools for the active page agent-browser record start demo.webm # Record session agent-browser profiler start # Start Chrome DevTools profiling agent-browser profiler stop trace.json # Stop and save profile (path optional)
YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).
ication](#restoring-authentication)
The fastest way to authenticate is to reuse cookies from a Chrome session you are already logged into.
Step 1: Start Chrome with remote debugging
# macOS
"/Applications/Google Chrome.app/Contents/MacOS/Google Chrome" --remote-debugging-port=9222
# Linux
google-chrome --remote-debugging-port=9222
# Windows
"C:\Program Files\Google\Chrome\Application\chrome.exe" --remote-debugging-port=9222
Log in to your target site(s) in this Chrome window as you normally would.
Security note:
--remote-debugging-portexposes full browser control on localhost. Any local process can connect and read cookies, execute JS, etc.
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
Clean up after automation
agent-browser cookies clear
rm -f ./auth-state.json
Use short-lived sessions for CI/CD
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
echo "*.auth-state.json" >> .gitignore
rm /tmp/auth-state.json
### 4. Timeout Long Sessions
The skill metadata references npx agent-browser without version pinning, so tool execution may resolve to an unreviewed package release at runtime. That expands the trust boundary from the reviewed skill content to the live npm ecosystem and makes compromise or drift materially more dangerous.
The manifest allowlists execution of npx agent-browser:* without pinning a specific package version, which permits whatever version is currently published or resolved at runtime to be fetched and executed. In an agent setting, that creates a supply-chain risk where a compromised upstream package or unexpected major-version change could execute arbitrary code with the agent's privileges.
The skill documents credential storage, plaintext session-state files, auto-connection to an already logged-in browser, downloads, screenshots, recording, and clipboard access, but does not foreground privacy and data-handling risks before those features are introduced. In an agent environment, that omission can cause operators or downstream models to invoke sensitive actions without understanding that secrets, tokens, local files, and user activity may be captured or persisted.
Clipboard read/write operations allow the skill to access or overwrite data outside the immediate browser page workflow, including secrets a user copied from other applications. For an agent, that broadens data access beyond the stated browser automation purpose and creates a path for exfiltration, credential capture, or destructive overwrites of user clipboard contents.
The documented eval capability enables arbitrary JavaScript execution in the browser context, which is broader than simple navigation and form interaction. In an agent workflow, this can be used to extract sensitive page data, manipulate application state, bypass intended guardrails, or relay untrusted page content back into the model context in more dangerous forms.
The configuration encourages persistent local profiles and saved settings, which can retain cookies, session tokens, browsing artifacts, and potentially proxy/auth configuration across runs. In a multi-task or multi-user agent environment, that persistence increases the chance of unintended session reuse, cross-task data leakage, and stale privileged state being silently applied.
Create agent-browser.json in the project root for persistent settings:
{
The basic login example shows a literal password value in a command, which normalizes unsafe credential handling and makes it easy for users to copy hardcoded secrets into shell history, docs, or scripts. In an agent/browser-automation skill, this is more dangerous because the documentation directly teaches operational auth workflows, so insecure examples are likely to be reused in real environments.
The OAuth example instructs direct entry of email and password during an SSO flow without an adjacent warning about handling IdP credentials safely. This can encourage users to script sensitive account credentials into automation, increasing risk of credential leakage through logs, transcripts, command history, and shared example code.
Network request inspection, custom headers, and credential-setting capabilities can reveal or transmit sensitive data such as authorization headers, cookies, or basic-auth credentials, yet the documentation gives no privacy or handling warning. In browser automation, this can facilitate inadvertent collection or disclosure of secrets during debugging, scraping, or test execution.
The cookie and storage commands expose direct read/write access to browser cookies and localStorage but provide no warning that these often contain session identifiers, CSRF tokens, or personal data. In an agent context, that omission increases the risk of accidental disclosure, unsafe logging, or destructive clearing of important browser state.
The documented eval functionality explicitly supports arbitrary JavaScript execution in the page context, including unrestricted scripts via base64 or stdin. In a browser-automation skill, this materially expands capability from UI interaction into code execution inside arbitrary web origins, enabling extraction of page data, access to DOM-visible secrets, and actions that bypass safer higher-level command constraints.
The state save/load commands are documented as persisting cookies, storage, and auth state without warning that the output file may contain session tokens and other sensitive authentication artifacts. This can lead agents or users to persist reusable credentials insecurely, making account takeover or unauthorized session reuse possible if the file is exposed.
Restoring saved browser state enables reuse of prior authenticated sessions, which is inherently sensitive because the state file may act as a portable login token. In this skill, session persistence is more dangerous because the tool is designed for autonomous browser actions, so loading compromised state can silently grant broad account access across sites.
agent-browser state save auth.json # Save cookies, storage, auth state
agent-browser state load auth.json # Restore saved state
The documentation describes capturing and saving Chrome performance traces but never warns that trace files can include sensitive telemetry such as visited URLs, timing of user interactions, JavaScript execution details, network-related metadata, and application-specific user timing marks. In an agent-driven browser automation context, those traces may be generated while logged into real services or interacting with user data, increasing the chance that operators store, share, or upload sensitive artifacts without realizing the exposure.
The documentation recommends embedding proxy credentials directly in the HTTP_PROXY URL without warning that environment variables and shell history can leak secrets to process listings, logs, crash reports, or child processes. In an agent/browser automation context, operators may copy this pattern into scripts and CI environments, increasing the chance of credential exposure and unauthorized proxy use.
The SOCKS5 authenticated proxy example also embeds credentials in ALL_PROXY and does not warn about secret handling risks. This can lead users to expose usernames and passwords through shell history, environment inspection, support bundles, or inherited process environments, which is especially relevant for an automation skill likely to run in shared developer or CI systems.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
# Restore saved state
agent-browser state load /path/to/auth-state.json
# Continue with authenticated session
The documentation encourages recording browser sessions for login workflows, debugging, and CI artifacts but does not warn that videos can capture credentials, session state, PII, internal URLs, or other sensitive on-screen data. In an agent-browser skill, this is more dangerous because agents may automate authenticated sessions and store artifacts automatically, increasing the chance of sensitive recordings being retained, shared, or uploaded to logs and build systems.
This workflow captures full-page screenshots, text, structure, and PDFs and saves them to local disk without any warning, minimization, or confirmation step around sensitive content. In a browser automation skill, this is meaningfully risky because pages may contain personal data, credentials, internal documents, or regulated information that gets persistently stored and later exposed through logs, backups, or shared workspaces.
The template documents loading a stored authentication state for protected pages without warning about the sensitivity of reusing authenticated sessions. That can cause the tool to capture privileged content under a user's session and save it locally, increasing the chance of unauthorized disclosure of account data, internal resources, or other protected material.
No suspicious patterns detected.