T09 · Insecure Skill Coding Practices
- Location
scripts/package_skill.py:61- Finding
Archive Output Path Traversal and Arbitrary File Overwrite
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is mostly a browser automation helper, but it overstates isolation while enabling control of existing or remote browsers and includes risky examples and helper scripts.
Install only if you are comfortable giving an agent browser automation authority. Prefer the isolated openclaw profile, avoid chrome mode unless you intentionally want the agent to access your logged-in browser, use trusted TLS-protected remote CDP/browserless endpoints only, avoid putting passwords or tokens on command lines, review uploads before running them, and treat the packaging helper as unsafe for untrusted skill directories.
scripts/package_skill.py:61Archive Output Path Traversal and Arbitrary File Overwrite
scripts/package_skill.py:97External File Disclosure Through Symlinks During Packaging
scripts/browser_action.py:14Sensitive Browser Input Disclosed in Error Logs and Process Arguments
references/configuration.md:181Unpinned Third-Party Package Installation and Execution
There is a clear description-behavior mismatch. The declared purpose says the skill provides browser hosting and automation capabilities, but the code shown only initializes folders and generates a markdown template for such a skill. Its actual purpose is scaffolding/setup for a browser-hosting skill, not delivering the runtime browser control capabilities described. This is a materially different primary purpose, so it should be flagged as a mismatch.
There is a clear mismatch between the declared purpose and the code's actual behavior. The description claims browser automation and web-control functionality, but the provided script only performs local packaging tasks: checking for required files, validating metadata, walking directories, and writing a zip-based .skill file. These are materially different capabilities and represent a different primary purpose. No browser control, network interaction, scraping, or UI testing logic appears in the code chunk.
The skill documents commands and bundled scripts that imply shell execution and local file interactions, yet it declares no explicit tool scope or permissions boundaries. In an agent setting, missing scope declarations can cause over-broad tool availability and make it harder to enforce least privilege or safely review what the skill is allowed to do.
The skill encourages automation of form filling, clicking, and submission against live websites without an explicit warning that these actions can send real data, trigger purchases, modify accounts, or violate site expectations. In an agent workflow, omission of this warning increases the chance of accidental high-impact real-world actions by users who assume the examples are harmless demonstrations.
The remote workstation and browserless examples route browsing activity, page content, cookies, and potentially credentials through external systems, but the skill does not prominently warn users about that exposure. This is dangerous because users may treat remote/browserless profiles as equivalent to local isolation and unknowingly send sensitive data to third-party or less-trusted infrastructure.
The security section asserts that browser control is restricted to localhost, but earlier sections explicitly describe remote CDP and hosted browser endpoints. This contradictory guidance can cause operators to make unsafe trust assumptions, exposing page content, credentials, session data, or browser control traffic to remote systems they believed were impossible.
The example demonstrates entering credentials and extracting post-login data, but it provides no warning that these actions may expose sensitive information through command history, logs, terminal scrollback, snapshots, or collection from authenticated pages. In a browser automation skill, normalized examples strongly influence user behavior, so omission of basic safety guidance can lead to accidental credential leakage or unauthorized handling of protected data.
The file upload example instructs users to upload a local file to a remote site without warning that the file contents will leave the local environment and may contain confidential or regulated data. In a browser-hosting automation context, this is especially risky because the workflow makes exfiltration-capable behavior appear routine and safe.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
The security language presents the skill as isolated and safe, but the chrome extension relay mode directly reuses the user's existing Chrome profile. In a browser automation skill, that contradiction is security-relevant because an agent may be granted powerful access to authenticated sessions and personal browsing data under the mistaken assumption of sandboxing.
The document explicitly states that the chrome profile controls an existing Chrome session and uses the user's existing Chrome profile, which contradicts the broader safety claim that browser use is isolated and does not affect the personal browser. This can mislead users or downstream agents into performing automation in a non-isolated context, risking data exposure, session misuse, or unintended modification of the user's active browsing state.
This code exposes actions such as click, type, drag, fill, evaluate, and close, which can modify web state or submit data, but it provides no user-facing disclosure beyond generic argument help. Although subprocess use is part of the skill's purpose, the script lacks any warning that these actions may interact with live sites, enter text, or trigger submissions.
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
"""Run openclaw browser command with given arguments."""
cmd = ["openclaw", "browser"] + args
try:
result = subprocess.run(cmd, capture_output=True, text=True, check=True)
return result.stdout.strip()
except subprocess.CalledProcessError as e:
print(f"Error running browser command: {e}", file=sys.stderr)
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
"""Run openclaw browser command with given arguments."""
cmd = ["openclaw", "browser"] + args
try:
result = subprocess.run(cmd, capture_output=True, text=True, check=True)
return result.stdout.strip()
except subprocess.CalledProcessError as e:
print(f"Error running browser command: {e}", file=sys.stderr)
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
def check_browser_status(profile="openclaw"):
"""Check browser status using openclaw CLI"""
try:
result = subprocess.run([
"openclaw", "browser",
"--browser-profile", profile,
"status", "--json"
The remote CDP examples show credentials embedded in URLs and tokenized remote endpoints without a prominent warning about the security implications of sending browser-debugging access over the network. If users expose CDP endpoints insecurely or reuse these patterns without TLS, network restrictions, or secret-handling safeguards, attackers could obtain browser control, session data, or embedded credentials.
No suspicious patterns detected.