Back to skill

Security audit

Browser Hosting

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a browser automation helper, but it overstates isolation while enabling control of existing or remote browsers and includes risky examples and helper scripts.

Install only if you are comfortable giving an agent browser automation authority. Prefer the isolated openclaw profile, avoid chrome mode unless you intentionally want the agent to access your logged-in browser, use trusted TLS-protected remote CDP/browserless endpoints only, avoid putting passwords or tokens on command lines, review uploads before running them, and treat the packaging helper as unsafe for untrusted skill directories.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/package_skill.py:61
Finding

Archive Output Path Traversal and Arbitrary File Overwrite

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/package_skill.py:97
Finding

External File Disclosure Through Symlinks During Packaging

Content
View full analysis
/home/victim/.openclaw/openclaw.json ``` 2. The victim runs the packaging script against that directory. 3. `os.walk()` includes the symlink in its file list. 4. The script performs no `is_symlink()` or resolved-path containment check. 5. `zf.write()` reads the symlink target and places its contents in the generated `.skill` archive. 6. The victim distributes or uploads the archive, disclosing the external file to its recipient. ### Impact Assessment The issue can disclose any local file readable by the packaging process if an attacker can place a corresponding symlink in the Skill tree. Potentially exposed data includes browser configuration, API tokens, credentials, SSH material, source code, and personal files. The vu ...[truncated 168 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/browser_action.py:14
Finding

Sensitive Browser Input Disclosed in Error Logs and Process Arguments

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
references/configuration.md:181
Finding

Unpinned Third-Party Package Installation and Execution

Content
View full analysis
Remediation
View remediation
``` 2. Commit and enforce a lockfile with integrity metadata, and use `npm ci` for reproducible installation. 3. Avoid global package installation. Execute the project-local pinned binary instead: ```bash npx --no-install playwright install chromium ``` 4. Document the trusted registry and configure package-manager provenance and signature verification where available. 5. Review transitive dependencies and use automated vulnerability and integrity scanning. 6. Pin the Docker image by immutable digest and ensure the Playwright tooling inside it corresponds to the reviewed version. 7. Warn users not to run installation commands with elevated privileges unless strictly necessary. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (16)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

There is a clear description-behavior mismatch. The declared purpose says the skill provides browser hosting and automation capabilities, but the code shown only initializes folders and generates a markdown template for such a skill. Its actual purpose is scaffolding/setup for a browser-hosting skill, not delivering the runtime browser control capabilities described. This is a materially different primary purpose, so it should be flagged as a mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

There is a clear mismatch between the declared purpose and the code's actual behavior. The description claims browser automation and web-control functionality, but the provided script only performs local packaging tasks: checking for required files, validating metadata, walking directories, and writing a zip-based .skill file. These are materially different capabilities and represent a different primary purpose. No browser control, network interaction, scraping, or UI testing logic appears in the code chunk.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
79% confidence
Finding

The skill documents commands and bundled scripts that imply shell execution and local file interactions, yet it declares no explicit tool scope or permissions boundaries. In an agent setting, missing scope declarations can cause over-broad tool availability and make it harder to enforce least privilege or safely review what the skill is allowed to do.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The skill encourages automation of form filling, clicking, and submission against live websites without an explicit warning that these actions can send real data, trigger purchases, modify accounts, or violate site expectations. In an agent workflow, omission of this warning increases the chance of accidental high-impact real-world actions by users who assume the examples are harmless demonstrations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The remote workstation and browserless examples route browsing activity, page content, cookies, and potentially credentials through external systems, but the skill does not prominently warn users about that exposure. This is dangerous because users may treat remote/browserless profiles as equivalent to local isolation and unknowingly send sensitive data to third-party or less-trusted infrastructure.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The security section asserts that browser control is restricted to localhost, but earlier sections explicitly describe remote CDP and hosted browser endpoints. This contradictory guidance can cause operators to make unsafe trust assumptions, exposing page content, credentials, session data, or browser control traffic to remote systems they believed were impossible.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The example demonstrates entering credentials and extracting post-login data, but it provides no warning that these actions may expose sensitive information through command history, logs, terminal scrollback, snapshots, or collection from authenticated pages. In a browser automation skill, normalized examples strongly influence user behavior, so omission of basic safety guidance can lead to accidental credential leakage or unauthorized handling of protected data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file upload example instructs users to upload a local file to a remote site without warning that the file contents will leave the local environment and may contain confidential or regulated data. In a browser-hosting automation context, this is especially risky because the workflow makes exfiltration-capable behavior appear routine and safe.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The security language presents the skill as isolated and safe, but the chrome extension relay mode directly reuses the user's existing Chrome profile. In a browser automation skill, that contradiction is security-relevant because an agent may be granted powerful access to authenticated sessions and personal browsing data under the mistaken assumption of sandboxing.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document explicitly states that the chrome profile controls an existing Chrome session and uses the user's existing Chrome profile, which contradicts the broader safety claim that browser use is isolated and does not affect the personal browser. This can mislead users or downstream agents into performing automation in a non-isolated context, risking data exposure, session misuse, or unintended modification of the user's active browsing state.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This code exposes actions such as click, type, drag, fill, evaluate, and close, which can modify web state or submit data, but it provides no user-facing disclosure beyond generic argument help. Although subprocess use is part of the skill's purpose, the script lacks any warning that these actions may interact with live sites, enter text, or trigger submissions.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/browser_action.py (reported line 18)May include surrounding context.

python
"""Run openclaw browser command with given arguments."""
    cmd = ["openclaw", "browser"] + args
    try:
        result = subprocess.run(cmd, capture_output=True, text=True, check=True)
        return result.stdout.strip()
    except subprocess.CalledProcessError as e:
        print(f"Error running browser command: {e}", file=sys.stderr)

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/browser_snapshot.py (reported line 18)May include surrounding context.

python
"""Run openclaw browser command with given arguments."""
    cmd = ["openclaw", "browser"] + args
    try:
        result = subprocess.run(cmd, capture_output=True, text=True, check=True)
        return result.stdout.strip()
    except subprocess.CalledProcessError as e:
        print(f"Error running browser command: {e}", file=sys.stderr)

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/browser_status.py (reported line 13)May include surrounding context.

python
def check_browser_status(profile="openclaw"):
    """Check browser status using openclaw CLI"""
    try:
        result = subprocess.run([
            "openclaw", "browser", 
            "--browser-profile", profile, 
            "status", "--json"

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The remote CDP examples show credentials embedded in URLs and tokenized remote endpoints without a prominent warning about the security implications of sending browser-debugging access over the network. If users expose CDP endpoints insecurely or reuse these patterns without TLS, network restrictions, or secret-handling safeguards, attackers could obtain browser control, session data, or embedded credentials.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.