Back to skill

Security audit

Bb Browser 0.6.0

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent for website data extraction, but it pulls community adapters and runs them in logged-in OpenClaw browser sessions, which deserves careful review before installation.

Install only if you trust bb-browser's adapter update source and are comfortable with adapters operating through browser sessions where you may already be logged in. Prefer a separate browser profile or logged-out session for sensitive sites, review adapter details before use, and avoid running it against private accounts or financial/work data unless you understand what data will be read or changed.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Error
Location
SKILL.md:18
Finding

Unpinned Community Adapters Execute in an Authenticated Browser Context

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 18-20
Vulnerability Type: Unverified third-party component retrieval
Risk Level: High

bash
# First time: pull community adapters
bb-browser site update

Technical Analysis

The skill instructs users to retrieve community-maintained adapters dynamically by running bb-browser site update. The documentation does not identify a trusted registry, pin adapter versions or revisions, require cryptographic signature or checksum verification, or describe a review and approval process.

Subsequent adapter commands run through OpenClaw's browser using --openclaw, and the documentation explicitly states that adapters can use the browser's existing login state. Consequently, the effective behavior introduced by an adapter can change after the skill itself has been reviewed. If the adapter distribution source, publisher account, or release pipeline is compromised, attacker-controlled adapter logic could be delivered to users and invoked within an authenticated browser context.

Attack Path

  1. An attacker compromises the community adapter registry, an adapter publisher, or its release pipeline, or otherwise succeeds in distributing a malicious adapter through the update channel.
  2. A user follows the documented first-time setup and runs bb-browser site update.
  3. The unpinned adapter is retrieved without a documented signature, checksum, source confirmation, or manual permission review.
  4. The user invokes the compromised adapter with bb-browser site ... --openclaw.
  5. The adapter executes through OpenClaw's browser and may interact with websites using the user's active authenticated sessions.
  6. Depending on the affected site's privileges and the browser integration's controls, the adapter may read authenticated data or perform unauthorized actions as the user.

Impact Assessment

Successful exploitation could expose information available thr ...[truncated 635 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin each adapter to a reviewed immutable version, commit digest, or content hash rather than implicitly accepting the latest release.
  2. Retrieve adapters only from a documented, allowlisted registry over authenticated transport.
  3. Require cryptographic signatures and verify both publisher identity and artifact integrity before installation or execution.
  4. Display the adapter's source, version, digest, requested browser permissions, and update changes before obtaining user approval.
  5. Apply least privilege by restricting adapters to explicitly authorized origins, tabs, HTTP methods, and data fields.
  6. Isolate adapter execution from unrelated authenticated sessions and use a separate browser profile where practical.
  7. Maintain a lockfile or equivalent manifest recording the exact reviewed adapter versions and hashes.
  8. Add rollback, revocation, and audit-log capabilities so compromised adapter releases can be disabled and investigated promptly.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill explicitly encourages extracting structured data from websites using the user's existing logged-in browser state, which can expose account-scoped or personal data without any warning about privacy, consent, or handling of authenticated content. In this context, the skill's broad support for many platforms and its emphasis on reusing browser sessions makes accidental over-collection or misuse of sensitive data more likely.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.