Back to skill

Security audit

aicloud-thought-proxy

Security checks for vulnerabilities and agentic risk

Overview

This skill is coherent, but it gives third-party web AIs and browser-automation tools a very broad path to influence local actions and authenticated browser sessions.

Install only if you are comfortable letting this skill control a browser session and use external web AI output to guide local execution. Use a dedicated browser profile logged in only to the chosen AI site, avoid sharing secrets or private code unless intentional, review every command/download/file write before approval, and prefer pinned/verified tool versions over latest-release installs.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:162
Finding

Untrusted Web AI Responses Can Direct Local Code and Command Execution

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
references/tool-installation.md:17
Finding

Unpinned Third-Party Bridge and Browser Extension Are Installed and Trusted

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
references/gecko-automation.md:25
Finding

Automation Reuses the User's Primary Authenticated Browser Profile

Content
View full analysis
" # Alternatively: # options.add_argument("-profile ") ``` ```json { "moz:firefoxOptions": { "args": ["-profile", ""] } } ``` The Chromium guide similarly recommends: ```text Connect to the user's existing browser instance through a remote debugging port, or reuse the profile directory, to preserve login state. ``` The connector is documented as supporting navigation, page reading, clicking, text entry, screenshots, tab enumeration, and page JavaScript or console execution. ### Technical Analysis The legitimate task only requires access to a selected AI website. Reusing the user's normal browser profile exposes a much larger security domain: cookies, active sessions, open tabs, history-derived state, extensions, and authenticated access to unrelated services. A general-purpose browser automation connector with tab enumeration and JavaScript capability is substantially more privileged than a dedicated browser profile authenticated only to the target AI service. This violates least privilege even if the Skill does not directly extract browser credential databases. The risk is amplified by the external-in ...[truncated 1468 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/gecko-automation.md:69
Finding

Predictable Unauthenticated Local WebDriver Endpoint Exposes Browser-Control Capability

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (19)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The overview says the local agent will create files, run scripts, download resources, and perform searches, but it lacks a clear up-front warning that the skill can modify the local system. Users reading only the description may not realize the skill can install tools, alter config files, write to disk, and execute downloaded code, which undermines informed consent.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/gecko-automation.md (reported line 81)May include surrounding context.

md
| `POST /session/{id}/element/{el}/click` | 点击元素 |
| `POST /session/{id}/element/{el}/value` | 输入文本 |
| `GET /session/{id}/screenshot` | 截图(base64) |
| `DELETE /session/{id}` | 关闭会话 |

Python 示例(仅标准库 urllib):

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README promotes a loop where a web AI produces steps and code while the local agent performs file creation, script execution, downloads, scraping, and web searches, yet it lacks a strong warning about possible system modification, malware introduction, data loss, or unwanted network activity. This is especially risky because it combines untrusted third-party model output with privileged local actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README explicitly describes forwarding user requirements to web-based third-party AIs, but does not present a clear privacy warning about disclosure of prompts, files, code snippets, or sensitive business data to external providers. In this skill's context, that omission is dangerous because the entire workflow depends on transmitting user content outside the local agent boundary.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The trigger guidance is broad enough that ordinary requests like 'open a web AI and collaborate' may activate a workflow that relays prompts to third-party AI sites and drives local execution. That creates an unsafe scope boundary: users may invoke the skill without understanding that their data may be sent externally and that the local agent may perform impactful actions based on external model output.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · README.md (reported line 304)May include surrounding context.

md
<a id="installing-the-driver-tools-when-missing-en"></a>
## Installing the Driver Tools (When Missing)

**Principle**: Agent installs its side automatically (with your consent) + you complete the browser side manually (plain‑language guidance). **Never installs without asking.**

### Channel A: Chromium → chrome-mcp (mcp-chrome)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill explicitly instructs the agent to run shell commands, install software, edit configuration, download binaries, and drive browsers, but it declares no tool scope restrictions. That mismatch increases the chance the skill runs with broader-than-necessary capabilities, making accidental or unsafe command execution more likely if the workflow is triggered incorrectly or influenced by untrusted web AI output.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The overview says the local agent will create files, run scripts, download resources, and perform searches, but it lacks a clear up-front warning that the skill can modify the local system. Users reading only the description may not realize the skill can install tools, alter config files, write to disk, and execute downloaded code, which undermines informed consent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases include broad concepts such as '网页版 AI', '节省 tokens', and asking another AI to plan while the local agent executes, which are common conversational intents. This can cause the skill to activate in contexts where the user did not intend browser automation, third-party data transfer, or local execution, increasing the risk of unintended actions.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The initial protocol message normalizes the idea that the agent will provide the user's requirements to the external web AI, making disclosure the default behavior. While this is central to the skill's design, presenting it as a standard first step without a privacy warning or minimization requirement increases the chance of oversharing sensitive user content.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The instruction to forward the user's requests 'in full' to a web AI creates a direct natural-language exfiltration channel to an external service. In this skill's context, the external model is intentionally used as a planning copilot, so unredacted prompts may include secrets, proprietary code, internal paths, logs, or personal data that do not need to leave the local environment.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The entire skill documentation is written in Chinese and does not indicate that another language can be used or that the locale is intentionally constrained. Under the policy rule for language/locale, this is a natural-language constraint presented without user opt-in or documented justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The file title and all instructional content are written exclusively in Chinese, with no indication that the user may choose another language or locale. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill instructions force a single language presentation throughout the file and do not indicate that users may choose another language or that the skill is intentionally limited to a Chinese-speaking context. Under the language/locale policy, a fixed language without opt-in or justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The instructions tell the user to install and connect a browser-control extension and explicitly state that the agent will then be able to control the browser, but they do not provide a clear warning about privacy, session exposure, or the risk of the agent accessing logged-in web content. In this skill’s context, that omission is more dangerous because the whole purpose is to drive a real user browser containing live accounts, cookies, and sensitive data across multiple AI services.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code file contains natural-language instructions, usage text, and output field explanations that force a specific language/locale for users. The policy requires flagging language or locale constraints when the skill does not offer opt-in or justify the restriction as region-specific.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/detect_browser.py (reported line 179)May include surrounding context.

python
try:
        import subprocess  # noqa: PLC0415

        out = subprocess.run(
            [
                "/System/Library/Frameworks/CoreServices.framework/Frameworks/"
                "LaunchServices.framework/Support/lsregister",

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/detect_browser.py (reported line 206)May include surrounding context.

python
try:
        import subprocess  # noqa: PLC0415

        out = subprocess.run(
            ["xdg-settings", "get", "default-web-browser"],
            capture_output=True,
            text=True,

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · LICENSE (reported line 12)May include surrounding context.

text
permit persons to whom the Software is furnished to do so.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED,
INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A
PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT
HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION
OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE

Static analysis

No suspicious patterns detected.