Back to skill

Security audit

browser

Security checks for vulnerabilities and agentic risk

Overview

This browser automation skill is purpose-aligned, but it needs Review because setup can execute unverified remote code, run arbitrary Docker content, and persist into local agent environments.

Review this before installing. Only run setup if you trust the bsession source and the uv installer, avoid --repo values you do not control, prefer a pinned reviewed repository, use --no-start until you inspect Docker Compose behavior, and do not pass sensitive VNC passwords on the command line. Also check that you are comfortable with it writing under ~/.bsession, ~/.claude, and ~/.openclaw.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T03 · Remote Payload Retrieval and Execution

Error
Location
scripts/install.sh:68
Finding

Unverified Remote Installer Is Executed Directly by the Shell

Content
View full analysis
Remediation
View remediation
" EXPECTED_SHA256="" TMP_DIR="$(mktemp -d)" trap 'rm -rf "$TMP_DIR"' EXIT curl --fail --location --proto '=https' \ --output "$TMP_DIR/uv-archive" \ "https:///uv/${UV_VERSION}/" printf '%s %s\n' "$EXPECTED_SHA256" "$TMP_DIR/uv-archive" | sha256sum --check --status || fail "uv artifact checksum verification failed" # Install only the verified artifact. ``` ]]>

T03 · Remote Payload Retrieval and Execution

Error
Location
scripts/install.sh:103
Finding

Arbitrary Remote Repository Content Is Built and Started Without Trust Verification

Content
View full analysis
/dev/null 2>&1; then info "Stopping existing agent-browser container..." docker rm -f agent-browser &>/dev/null || true # Clean up orphan networks docker compose down --remove-orphans &>/dev/null 2>&1 || true fi info "Starting container..." docker compose up -d info "Container started." ``` ### Technical Analysis The `--repo` option accepts an arbitrary Git URL. The retrieved repository is not restricted to an approved host, pinned to an immutable commit, checked against an expected hash, or verified through signed commits or tags. The script only checks whether expected filenames such as `Dockerfile`, `docker-compose.yml`, and `entrypoint.sh` exist. Those checks do not establish the integrity or safety of their contents. The downloaded repository controls Docker build instructions, Compose service definitions, entrypoints, volume mounts, exposed ports, capabilities, and runti ...[truncated 2126 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/install.sh:40
Finding

VNC Password Is Accepted Through Process Arguments and Stored Without Enforced File Permissions

Content
View full analysis
> "$BSESSION_HOME/.env" fi info "VNC password configured." else info "No VNC password set (open access)." fi ``` ### Technical Analysis Command-line arguments are an inappropriate transport for secrets. A literal password may be retained in shell history and can be exposed through process inspection facilities while the installer is running. Automation systems may also log complete command invocations. The resulting password is written as plaintext to `~/.bsession/.env`. Creating the file with `touch` does not enforce mode `0600`; its effective permissions depend on the user's cur ...[truncated 1810 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
Findings (27)

Chaining Abuse

High
Category
Tool Misuse
Confidence
97% confidence
Finding

Piping curl output directly into sh is exactly the kind of dangerous chaining that removes any inspection or verification boundary between download and execution. A compromised response results in immediate arbitrary command execution on the host.

Content

Scanner excerpt · scripts/install.sh (reported line 70)May include surrounding context.

sh
info "Checking uv..."
if ! check uv; then
    info "Installing uv..."
    curl -LsSf https://astral.sh/uv/install.sh | sh
    export PATH="$HOME/.local/bin:$PATH"
    if ! check uv; then
        fail "uv installed but not on PATH. Add ~/.local/bin to your PATH and rerun."

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/install.sh (reported line 161)May include surrounding context.

sh
info "Created docker-compose.override.yml for custom workspace: $WORKSPACE_DIR"
else
    # Remove stale override if workspace is default
    rm -f "$BSESSION_HOME/docker-compose.override.yml"
fi
info "Workspace directories ready: $WORKSPACE_DIR"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/install.sh (reported line 165)May include surrounding context.

sh
fi
info "Workspace directories ready: $WORKSPACE_DIR"

# ── Step 5: Configure .env ───────────────────────────────────────────
if [[ ! -f "$BSESSION_HOME/.env" ]]; then
    touch "$BSESSION_HOME/.env"
fi

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/install.sh (reported line 166)May include surrounding context.

sh
info "Workspace directories ready: $WORKSPACE_DIR"

# ── Step 5: Configure .env ───────────────────────────────────────────
if [[ ! -f "$BSESSION_HOME/.env" ]]; then
    touch "$BSESSION_HOME/.env"
fi

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/install.sh (reported line 167)May include surrounding context.

sh
info "Workspace directories ready: $WORKSPACE_DIR"

# ── Step 5: Configure .env ───────────────────────────────────────────
if [[ ! -f "$BSESSION_HOME/.env" ]]; then
    touch "$BSESSION_HOME/.env"
fi

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/install.sh (reported line 171)May include surrounding context.

sh
info "Workspace directories ready: $WORKSPACE_DIR"

# ── Step 5: Configure .env ───────────────────────────────────────────
if [[ ! -f "$BSESSION_HOME/.env" ]]; then
    touch "$BSESSION_HOME/.env"
fi

Credential Access

High
Category
Privilege Escalation
Confidence
77% confidence
Finding

The script writes the VNC password directly into a plaintext .env file and interpolates it unescaped into a sed replacement, which can corrupt the file or expose the secret to other local users/processes depending on permissions. In a browser automation context, compromised VNC credentials can grant interactive access to the automation environment.

Content

Scanner excerpt · scripts/install.sh (reported line 172)May include surrounding context.

sh
if [[ -n "$VNC_PASSWORD" ]]; then
    if grep -q '^VNC_PASSWORD=' "$BSESSION_HOME/.env"; then
        sed -i.bak "s/^VNC_PASSWORD=.*/VNC_PASSWORD=$VNC_PASSWORD/" "$BSESSION_HOME/.env" && rm -f "$BSESSION_HOME/.env.bak"
    else
        echo "VNC_PASSWORD=$VNC_PASSWORD" >> "$BSESSION_HOME/.env"
    fi

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/install.sh (reported line 172)May include surrounding context.

sh
if [[ -n "$VNC_PASSWORD" ]]; then
    if grep -q '^VNC_PASSWORD=' "$BSESSION_HOME/.env"; then
        sed -i.bak "s/^VNC_PASSWORD=.*/VNC_PASSWORD=$VNC_PASSWORD/" "$BSESSION_HOME/.env" && rm -f "$BSESSION_HOME/.env.bak"
    else
        echo "VNC_PASSWORD=$VNC_PASSWORD" >> "$BSESSION_HOME/.env"
    fi

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · scripts/install.sh (reported line 172)May include surrounding context.

sh
if [[ -n "$VNC_PASSWORD" ]]; then
    if grep -q '^VNC_PASSWORD=' "$BSESSION_HOME/.env"; then
        sed -i.bak "s/^VNC_PASSWORD=.*/VNC_PASSWORD=$VNC_PASSWORD/" "$BSESSION_HOME/.env" && rm -f "$BSESSION_HOME/.env.bak"
    else
        echo "VNC_PASSWORD=$VNC_PASSWORD" >> "$BSESSION_HOME/.env"
    fi

Credential Access

High
Category
Privilege Escalation
Confidence
74% confidence
Finding

Appending VNC_PASSWORD directly to .env stores authentication material in plaintext without enforcing restrictive permissions. This is not credential theft, but it is insecure secret handling that can expose access to the browser session if the file is readable by others.

Content

Scanner excerpt · scripts/install.sh (reported line 174)May include surrounding context.

sh
if grep -q '^VNC_PASSWORD=' "$BSESSION_HOME/.env"; then
        sed -i.bak "s/^VNC_PASSWORD=.*/VNC_PASSWORD=$VNC_PASSWORD/" "$BSESSION_HOME/.env" && rm -f "$BSESSION_HOME/.env.bak"
    else
        echo "VNC_PASSWORD=$VNC_PASSWORD" >> "$BSESSION_HOME/.env"
    fi
    info "VNC password configured."
else

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
97% confidence
Finding

The skill clearly instructs the agent to execute shell and Docker commands, but it declares no explicit tool scope such as allowed-tools or permissions. That mismatch weakens policy enforcement and increases the chance the skill will be invoked with broader command execution capability than users expect, especially because it is marked user-invocable and global.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
95% confidence
Finding

The skill explicitly supports creating one-shot or recurring automations and debugging existing sessions, which introduces persistence through saved scripts, configuration, and potentially long-running browser jobs. In this context persistence is part of the intended functionality, but it still expands attack surface because a compromised or misdirected session can continue operating or collecting data after the initial interaction.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: browser
description: Browser automation — setup the bsession environment, fetch info from a website (one-shot), create scripted automations (one-shot or recurring), or debug existing sessions. Works from any repo.
user-invocable: true
metadata: {"openclaw":{"requires":{"bins":["docker"]}}}
---

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The description is broad enough to match many browsing, scraping, setup, or debugging requests, which can cause unintended activation of a skill that runs shell and Docker commands. Because the skill works from any repo and is user-invocable, accidental routing into a high-capability automation path is more dangerous than for a narrowly described skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The setup flow runs an install script that performs Docker checks, installs dependencies, builds images, starts containers, and configures the CLI, yet the skill description does not clearly warn about local environment modification. For a global, user-invocable skill, omitting that warning increases the risk of users triggering impactful shell actions without realizing their scope.

Content

No source excerpt is available for this finding.

Internal Network Request

Medium
Category
Server-Side Request Forgery
Confidence
70% confidence
Finding

Code issues a request to a loopback, link-local, or private-range host. This can reach internal services not meant to be exposed and is a common SSRF pivot.

Content

Scanner excerpt · SKILL.md (reported line 126)May include surrounding context.

md
docker exec agent-browser python3 -c "
import urllib.request
try:
    urllib.request.urlopen('http://localhost:9222/json/version', timeout=2)
    print('IN_USE')
except:
    print('FREE')

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill scaffolds scripts and configuration files and supports sending results to webhooks, but the skill description does not warn users that it may create persistent files or transmit extracted data externally. This undermines informed consent and can lead to unintentional persistence or exfiltration of sensitive browsing data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script downloads and executes a remote shell script via curl | sh, giving the remote server immediate code execution on the host with no integrity verification or user confirmation. If the upstream site, network path, or installer content is compromised, the user's machine is fully exposed.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The script forcibly removes any existing container named agent-browser without warning or confirmation. This can destroy state, disrupt unrelated workloads using the same name, and create an unsafe precedent of destructive actions during installation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The installer modifies directories for multiple agent platforms by copying SKILL metadata and install scripts into ~/.claude and ~/.openclaw, which exceeds merely setting up the local browser runtime. Cross-platform persistence and workspace modification increase supply-chain and trust-boundary risk because installing one skill silently propagates executable content into other tool ecosystems.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · scripts/install.sh (reported line 246)May include surrounding context.

sh
# Find the repo source (for SKILL.md files)
REPO_SOURCE=""
if [[ -f "$TMPDIR/bsession/.claude/skills/browser/SKILL.md" ]]; then
    REPO_SOURCE="$TMPDIR/bsession"
elif [[ -f "$BSESSION_HOME/.claude/skills/browser/SKILL.md" ]]; then
    REPO_SOURCE="$BSESSION_HOME"

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · scripts/install.sh (reported line 248)May include surrounding context.

sh
# Find the repo source (for SKILL.md files)
REPO_SOURCE=""
if [[ -f "$TMPDIR/bsession/.claude/skills/browser/SKILL.md" ]]; then
    REPO_SOURCE="$TMPDIR/bsession"
elif [[ -f "$BSESSION_HOME/.claude/skills/browser/SKILL.md" ]]; then
    REPO_SOURCE="$BSESSION_HOME"

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · scripts/install.sh (reported line 257)May include surrounding context.

sh
# Find the repo source (for SKILL.md files)
REPO_SOURCE=""
if [[ -f "$TMPDIR/bsession/.claude/skills/browser/SKILL.md" ]]; then
    REPO_SOURCE="$TMPDIR/bsession"
elif [[ -f "$BSESSION_HOME/.claude/skills/browser/SKILL.md" ]]; then
    REPO_SOURCE="$BSESSION_HOME"

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · scripts/install.sh (reported line 258)May include surrounding context.

sh
# Find the repo source (for SKILL.md files)
REPO_SOURCE=""
if [[ -f "$TMPDIR/bsession/.claude/skills/browser/SKILL.md" ]]; then
    REPO_SOURCE="$TMPDIR/bsession"
elif [[ -f "$BSESSION_HOME/.claude/skills/browser/SKILL.md" ]]; then
    REPO_SOURCE="$BSESSION_HOME"

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · scripts/install.sh (reported line 272)May include surrounding context.

sh
# Find the repo source (for SKILL.md files)
REPO_SOURCE=""
if [[ -f "$TMPDIR/bsession/.claude/skills/browser/SKILL.md" ]]; then
    REPO_SOURCE="$TMPDIR/bsession"
elif [[ -f "$BSESSION_HOME/.claude/skills/browser/SKILL.md" ]]; then
    REPO_SOURCE="$BSESSION_HOME"

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · scripts/install.sh (reported line 273)May include surrounding context.

sh
# Find the repo source (for SKILL.md files)
REPO_SOURCE=""
if [[ -f "$TMPDIR/bsession/.claude/skills/browser/SKILL.md" ]]; then
    REPO_SOURCE="$TMPDIR/bsession"
elif [[ -f "$BSESSION_HOME/.claude/skills/browser/SKILL.md" ]]; then
    REPO_SOURCE="$BSESSION_HOME"

Static analysis

No suspicious patterns detected.