Back to skill

Security audit

web-access

Security checks for vulnerabilities and agentic risk

Overview

This skill openly provides powerful browser automation, but it also leaves a high-authority local browser-control service running without strong access controls.

Install only if you are comfortable giving the skill control over your logged-in browser. Use a separate browser profile for sensitive accounts, avoid letting it search history/bookmarks unless you explicitly need that, do not use arbitrary local file uploads with untrusted sites, and stop the CDP proxy after use if you do not want a local browser-control API left running.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/cdp-proxy.mjs:323
Finding

Unauthenticated Local API Enables Cross-User Control of Authenticated Browser Sessions

Content
View full analysis

Vulnerability Details

File Location: scripts/cdp-proxy.mjs:323-585
Vulnerability Type: Missing authentication and authorization on a privileged browser-control API
Risk Level: High

Technical Analysis

The CDP proxy exposes a loopback HTTP service without authenticating callers or authorizing operations. Although it binds only to 127.0.0.1, loopback is generally shared by all users and processes on the host rather than isolated to the operating-system account that launched the proxy.

The request handler accepts endpoint paths, query parameters, and bodies from any process able to connect to port 3456:

js
const server = http.createServer(async (req, res) => {
  const parsed = new URL(req.url, `http://localhost:${PORT}`);
  const pathname = parsed.pathname;
  const q = Object.fromEntries(parsed.searchParams);
  if (q.target) touchTab(q.target);

  res.setHeader('Content-Type', 'application/json; charset=utf-8');

  try {
    // /health 不需要连接浏览器
    if (pathname === '/health') {
      const connected = ws && (ws.readyState === WS.OPEN || ws.readyState === 1);
      res.end(JSON.stringify({
        status: 'ok',
        connected,
        browser: connectedBrowser,
        sessions: sessions.size,
        managedTabs: managedTabs.size,
        chromePort,
      }));
      return;
    }

    await connect();

    // GET /targets - 列出所有页面
    if (pathname === '/targets') {
      const resp = await sendCDP('Target.getTargets');
      const pages = resp.result.targetInfos.filter(t => t.type === 'page');
      res.end(JSON.stringify(pages, null, 2));
    }

The /targets endpoint discloses every browser page and its target identifier. Those identifiers can then be supplied to /eval, which executes arbitrary JavaScript in the selected page:

js
else if (pathname === '/eval') {
  const sid = await ensureSession(q.target);
  const body = await readBody(req);
...[truncated 4925 chars]
Remediation
View remediation

Remediation Suggestions

  1. Generate a cryptographically random secret for each proxy launch and require it as a bearer token on every endpoint, including read-only endpoints such as /health and /targets.
  2. Store the token in an owner-only file with mode 0600, or transfer it through an inherited file descriptor rather than exposing it in process arguments.
  3. Prefer an owner-restricted Unix domain socket on Unix-like systems or an access-controlled named pipe on Windows. This permits enforcement using operating-system peer identity.
  4. Enforce strict Origin validation and reject browser-originated requests unless explicitly authorized. Authentication must remain the primary control because origin checks alone do not protect against local native processes.
  5. Restrict privileged endpoints to tabs created and tracked by the proxy. Do not permit arbitrary target IDs returned by the browser to be attached without explicit authorization.
  6. Constrain /setFiles inputs to user-approved files or an allowlisted directory. Resolve paths canonically and reject paths outside the authorized boundary.
  7. Remove caller-selected filesystem destinations from /screenshot, or constrain output to a dedicated directory using exclusive file creation and canonical path validation.
  8. Use POST or DELETE for state-changing operations and add request size limits, method checks, and structured schema validation.
  9. Stop the proxy when the authorized task ends, or enforce a short inactivity shutdown period, rather than leaving a high-authority service detached indefinitely.
  10. Add automated tests proving that unauthenticated requests, requests from unauthorized origins, arbitrary target IDs, and paths outside approved directories are rejected.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (33)

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

Natural-language instructions to search local browser history and bookmarks create a direct mechanism for extracting private browsing records and discovering internal resources. Because requests like 'the page I viewed before' are easy to phrase innocuously, the skill lowers the barrier to exfiltrating sensitive local data.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The instruction to preserve full URLs including session-related parameters risks capturing and propagating access tokens, signed links, or other secrets in logs, outputs, prompts, or downstream tools. Even if intended to maintain functionality, retaining raw authenticated URLs materially increases credential leakage risk.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script intentionally reads local Chrome/Edge bookmarks and history to discover URLs that public search cannot reach, explicitly including internal systems, SSO backends, and intranet domains. In a web-access skill, harvesting local browser artifacts is unrelated to normal remote browsing and materially expands access into sensitive user data and internal infrastructure.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill exposes shell, network, and environment-backed capabilities but does not declare an explicit tool scope or permission boundary. That makes it easier for an agent to invoke powerful local and network actions outside a clearly constrained contract, increasing the chance of misuse or unintended data access.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

Labeling the skill as 'Universal web access' without tight trigger constraints encourages overly broad activation for many browsing-related tasks. In combination with powerful browser and shell capabilities, that broad scope increases the risk of the skill being used in situations where a narrower, safer tool would suffice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Natural-language policy checks apply to all file types. The operational instructions are effectively forced into a specific language/locale, with no opt-in or alternative language guidance for users or agents that may expect another language.

Content

No source excerpt is available for this finding.

Ssd 4

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The workflow normalizes bypassing anti-scraping controls and using the user's authenticated browser context to access content that static methods cannot reach. This increases the likelihood of unauthorized or policy-violating access and raises the risk of exposing account-scoped or restricted data through automation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill explicitly instructs the agent to query local browser history and bookmarks, which can reveal private browsing activity, internal systems, and sensitive URLs unrelated to the immediate user request. This exceeds normal web-access behavior and creates a natural path for unnecessary collection of local private data.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 123)May include surrounding context.

Proxy API

所有操作通过 curl 调用 HTTP API:

bash
# 列出用户已打开的 tab

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill tells the agent to write and update local site-pattern knowledge files, introducing persistent local modification beyond transient web access. Persistent writes can store sensitive observations from authenticated sessions or create a covert channel for future tasks.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/cdp-api.md (reported line 15)May include surrounding context.

GET /health

健康检查,返回连接状态。

bash
curl -s http://localhost:3456/health

GET /targets

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The API explicitly exposes arbitrary JavaScript execution in any attached browser page via /eval. In a web-access skill, this is a powerful capability that can read page DOM, scrape sensitive data from authenticated sessions, trigger privileged browser actions, and manipulate workflows far beyond simple fetch/search behavior; if an agent or prompt is compromised, /eval becomes a general-purpose post-login data access primitive.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The documented clickAt and setFiles capabilities are designed to simulate real user gestures and bypass normal browser UI controls such as file dialogs. In context, this materially increases the ability to evade anti-automation safeguards and perform impactful actions on sites while reducing user visibility and consent checks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The API supports writing screenshots to arbitrary local file paths, setting local files into upload inputs, and closing browser tabs, all of which can affect local data or active user state. The documentation presents these as routine operations without clear warnings, safety boundaries, or path restrictions, increasing the chance of destructive or privacy-impacting misuse.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/migration-2.5.3.md (reported line 6)May include surrounding context.

TL;DR

diff
- curl -s "http://localhost:3456/new?url=https://example.com"
+ curl -s -X POST --data-raw 'https://example.com' http://localhost:3456/new

- curl -s "http://localhost:3456/navigate?target=ID&url=https://example.com"

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/migration-2.5.3.md (reported line 39)May include surrounding context.

md
| 场景 | 旧(v2.5.2) | 新(v2.5.3) |
|---|---|---|
| 简单 URL | `curl ".../new?url=https://example.com"` | `curl -X POST --data-raw 'https://example.com' .../new` |
| URL 含 query | `curl ".../new?url=https://xhs.com/explore/x?xsec_token=ABC"` ⚠️ token 丢失 | `curl -X POST --data-raw 'https://xhs.com/explore/x?xsec_token=ABC' .../new` ✓ |
| URL 含 `#` fragment | `curl ".../new?url=https://app/page#sec"` ⚠️ fragment 丢失 | `curl -X POST --data-raw 'https://app/page#sec' .../new` ✓ |

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/migration-2.5.3.md (reported line 40)May include surrounding context.

md
| 场景 | 旧(v2.5.2) | 新(v2.5.3) |
|---|---|---|
| 简单 URL | `curl ".../new?url=https://example.com"` | `curl -X POST --data-raw 'https://example.com' .../new` |
| URL 含 query | `curl ".../new?url=https://xhs.com/explore/x?xsec_token=ABC"` ⚠️ token 丢失 | `curl -X POST --data-raw 'https://xhs.com/explore/x?xsec_token=ABC' .../new` ✓ |
| URL 含 `#` fragment | `curl ".../new?url=https://app/page#sec"` ⚠️ fragment 丢失 | `curl -X POST --data-raw 'https://app/page#sec' .../new` ✓ |

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/migration-2.5.3.md (reported line 41)May include surrounding context.

md
| 场景 | 旧(v2.5.2) | 新(v2.5.3) |
|---|---|---|
| 简单 URL | `curl ".../new?url=https://example.com"` | `curl -X POST --data-raw 'https://example.com' .../new` |
| URL 含 query | `curl ".../new?url=https://xhs.com/explore/x?xsec_token=ABC"` ⚠️ token 丢失 | `curl -X POST --data-raw 'https://xhs.com/explore/x?xsec_token=ABC' .../new` ✓ |
| URL 含 `#` fragment | `curl ".../new?url=https://app/page#sec"` ⚠️ fragment 丢失 | `curl -X POST --data-raw 'https://app/page#sec' .../new` ✓ |

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/migration-2.5.3.md (reported line 47)May include surrounding context.

md
| 场景 | 旧(v2.5.2) | 新(v2.5.3) |
|---|---|---|
| 简单 URL | `curl ".../new?url=https://example.com"` | `curl -X POST --data-raw 'https://example.com' .../new` |
| URL 含 query | `curl ".../new?url=https://xhs.com/explore/x?xsec_token=ABC"` ⚠️ token 丢失 | `curl -X POST --data-raw 'https://xhs.com/explore/x?xsec_token=ABC' .../new` ✓ |
| URL 含 `#` fragment | `curl ".../new?url=https://app/page#sec"` ⚠️ fragment 丢失 | `curl -X POST --data-raw 'https://app/page#sec' .../new` ✓ |

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/cdp-proxy.mjs (reported line 362)May include surrounding context.

js
| 场景 | 旧(v2.5.2) | 新(v2.5.3) |
|---|---|---|
| 简单 URL | `curl ".../new?url=https://example.com"` | `curl -X POST --data-raw 'https://example.com' .../new` |
| URL 含 query | `curl ".../new?url=https://xhs.com/explore/x?xsec_token=ABC"` ⚠️ token 丢失 | `curl -X POST --data-raw 'https://xhs.com/explore/x?xsec_token=ABC' .../new` ✓ |
| URL 含 `#` fragment | `curl ".../new?url=https://app/page#sec"` ⚠️ fragment 丢失 | `curl -X POST --data-raw 'https://app/page#sec' .../new` ✓ |

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/cdp-proxy.mjs (reported line 401)May include surrounding context.

js
| 场景 | 旧(v2.5.2) | 新(v2.5.3) |
|---|---|---|
| 简单 URL | `curl ".../new?url=https://example.com"` | `curl -X POST --data-raw 'https://example.com' .../new` |
| URL 含 query | `curl ".../new?url=https://xhs.com/explore/x?xsec_token=ABC"` ⚠️ token 丢失 | `curl -X POST --data-raw 'https://xhs.com/explore/x?xsec_token=ABC' .../new` ✓ |
| URL 含 `#` fragment | `curl ".../new?url=https://app/page#sec"` ⚠️ fragment 丢失 | `curl -X POST --data-raw 'https://app/page#sec' .../new` ✓ |

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The code intentionally intercepts browser Fetch events and fails requests to the local Chrome debugging port so websites cannot detect the automation environment. This is anti-detection behavior beyond ordinary browsing automation and meaningfully increases abuse potential for scraping, bot evasion, and stealthy interaction with login-protected sites.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The /clickAt endpoint uses Input.dispatchMouseEvent to synthesize browser-level clicks and the comments explicitly note it can bypass automation detection and trigger privileged UI flows such as file dialogs. That capability enables websites to be interacted with in ways specifically designed to evade defenses and can be chained with other endpoints for deceptive or unauthorized automation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The /setFiles endpoint lets a caller provide arbitrary local filesystem paths and inject those files into upload controls on any loaded website. This can exfiltrate host data to remote services, especially dangerous because the same proxy controls authenticated browser sessions and can submit uploads under the user's identity.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This file upload capability has no built-in user-facing warning, consent flow, or confirmation of which local files will be sent to which site. The absence of consent controls materially increases the likelihood of silent data exfiltration from the host to arbitrary web origins.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec, suspicious.env_credential_access

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/check-deps.mjs:69

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/check-deps.mjs:9