Back to skill

Security audit

Coco Playwright Stealth 1.0.0

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed Playwright scraping skill, but it runs untrusted pages with weakened browser protections and broad URL access that users should review before installing.

Install only if you intend to run a stealth web scraper. Use it in an isolated environment with restricted network access, avoid private or sensitive URLs, review saved screenshots/HTML, and do not run the optional unpinned third-party skill instructions without separately reviewing that package.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/playwright-simple.js:12
Finding

Unrestricted Browser Navigation Enables Server-Side Request Forgery

Content
View full analysis
'); process.exit(1); } (async () => { console.log('🚀 啟動 Playwright 簡單版爬蟲...'); const startTime = Date.now(); const browser = await chromium.launch({ headless: process.env.HEADLESS !== 'false' }); const page = await browser.newPage(); console.log(`📱 導航到: ${url}`); await page.goto(url, { waitUntil: 'domcontentloaded' }); console.log(`⏳ 等待 ${waitTime}ms...`); await page.waitForTimeout(waitTime); // 擷取基本資訊 const result = await page.evaluate(() => { return { title: document.title, url: window.location.href, content: document.body.innerText.substring(0, 5000), metaDescription: document.querySelector('meta[name="description"]')?.content || '', }; }); ``` The stealth implementation follows the same unrestricted navigation pattern and returns extracted page data: ```javascript const url = process.argv[2]; const response = await page.goto(url, { waitUntil: 'domcontentloaded', timeout: 30000, }); const result = await page.evaluate(() => { return { title: document.title, url: window.location.href, htmlLength: document.documentElement.outerHTML.length, contentPreview: document.body.innerText.substring(0, 1000), }; }); ``` ### Technical Analysis All three scraper implementations accept a URL directly from a command-line argument and navigate to it without validating: - The URL scheme - The requested hostname - The resolved ...[truncated 2188 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/playwright-stealth.js:43
Finding

Chromium Sandbox and Site Isolation Are Explicitly Disabled

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:87
Finding

Documentation Installs and Executes an Unpinned Third-Party Skill

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (41)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill markets itself as a general scraping solution but documents stealth behavior, local file writes, custom user agents, and anti-bot evasion without clearly framing those as sensitive behaviors. Misrepresentation of scope and side effects can lead users to run the skill in contexts they would otherwise avoid, undermining informed consent and safe deployment.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

The skill markets itself as a general scraping solution but documents stealth behavior, local file writes, custom user agents, and anti-bot evasion without clearly framing those as sensitive behaviors. Misrepresentation of scope and side effects can lead users to run the skill in contexts they would otherwise avoid, undermining informed consent and safe deployment.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 20)May include surrounding context.

md
| **Cloudflare Protected** | High | **Playwright Stealth** ⭐ | `scripts/playwright-stealth.js` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 74)May include surrounding context.

md
| **Cloudflare Protected** | High | **Playwright Stealth** ⭐ | `scripts/playwright-stealth.js` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 108)May include surrounding context.

md
| **Cloudflare Protected** | High | **Playwright Stealth** ⭐ | `scripts/playwright-stealth.js` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 126)May include surrounding context.

md
| **Cloudflare Protected** | High | **Playwright Stealth** ⭐ | `scripts/playwright-stealth.js` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 141)May include surrounding context.

md
| **Cloudflare Protected** | High | **Playwright Stealth** ⭐ | `scripts/playwright-stealth.js` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 147)May include surrounding context.

md
| **Cloudflare Protected** | High | **Playwright Stealth** ⭐ | `scripts/playwright-stealth.js` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 150)May include surrounding context.

md
| **Cloudflare Protected** | High | **Playwright Stealth** ⭐ | `scripts/playwright-stealth.js` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 153)May include surrounding context.

md
| **Cloudflare Protected** | High | **Playwright Stealth** ⭐ | `scripts/playwright-stealth.js` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 192)May include surrounding context.

md
| **Cloudflare Protected** | High | **Playwright Stealth** ⭐ | `scripts/playwright-stealth.js` |

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · test.sh (reported line 43)May include surrounding context.

sh
echo ""

# 清理
rm -f /tmp/test-*.json screenshot-*.png

echo "✅ 所有測試通過!"

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The README explicitly promotes anti-bot evasion techniques and saving screenshots/HTML, but does not warn about legal, policy, privacy, or data-handling implications. In a scraping skill, that omission materially increases misuse risk because users are encouraged to bypass detection and persist captured content without guidance on authorization, sensitive data handling, or terms-of-service compliance.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file advertises support for saving screenshots and HTML, which can affect user data and system storage, but it does not include any warning about local file creation or the sensitivity of captured page contents. Under the markdown criteria for missing user warnings, data-affecting behavior should be disclosed to users.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README shows SCREENSHOT_PATH and SAVE_HTML=true usage, which instructs the skill to persist page data locally, but it omits any warning about storing potentially sensitive website content. For markdown files, behaviors affecting user data or system integrity should be accompanied by clear warnings.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill documents environment-variable-driven behavior and code-like capabilities but declares no explicit tool scope or permissions. This creates an integrity and review gap: operators cannot easily tell what the skill may access or influence, which increases the chance of unsafe execution or privilege creep.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

Using npx playwright without pinning a version makes installation and execution depend on whatever package version is current at runtime. This weakens supply-chain integrity and reproducibility, and a compromised or breaking upstream release could alter behavior unexpectedly.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.