Back to skill

Security audit

talaria

Security checks for vulnerabilities and agentic risk

Overview

Talaria is a disclosed, opt-in Playwright stealth wrapper with meaningful dual-use risk but clear authorized-use boundaries and no hidden persistence or exfiltration behavior in the inspected files.

Install only if you need stealth Playwright automation for sites you own or are explicitly allowed to test. Treat proxy credentials as sensitive, avoid using it for generic scraping or bypassing access controls, and review output paths before saving screenshots or HTML because the CLI writes to the paths you provide.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (7)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 45)May include surrounding context.

md
- Expose `launchStealthBrowser()` (API) and `scripts/cli.js` (visit / screenshot / HTML / JSON)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 59)May include surrounding context.

md
Before any command, resolve the directory that contains this `SKILL.md` and use it as `$SKILL_DIR` below.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill declares environment-variable access in metadata and operational instructions but does not define an explicit tool-scope/permissions model such as allowed-tools or permissions. That creates a governance gap: an agent runtime may permit broader-than-intended access or make it harder to enforce least privilege, especially because the skill handles proxy credentials and browser automation. The surrounding text is safety-conscious, which lowers suspicion, but the omission is still a real policy/control weakness.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The package description markets the skill as a general 'stealth evasion' tool for agents, which broadens its apparent purpose beyond the narrower authorized-use restriction stated in the skill metadata. That mismatch can enable or normalize misuse for unauthorized scraping or anti-bot evasion, especially because package metadata is what downstream users and registries often see first.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The manifest describes a wrapper whose purpose is to enable Playwright stealth behavior when explicitly needed for authorized testing. In addition to stealth browser setup, the code pulls runtime behavior and proxy credentials from process environment variables, which introduces access to external configuration/secrets beyond what is necessary for the stated purpose in the manifest.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This code reads proxy server settings and credentials from environment variables and later launches a browser with a stealth plugin, but there is no confirmation prompt, user-facing log, or warning comment explaining these privacy- and integrity-relevant behaviors. The existing docstring describes parameters but does not disclose that the skill is designed to evade bot detection or consume sensitive proxy credentials.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The primary natural-language docstring for the exported function is written in Portuguese, which imposes a specific language on maintainers or users without any indication of language choice or opt-in. Under the stated policy, forcing a specific language can be a locale/language policy violation when not justified or made optional.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.