Back to skill

Security audit

Webwright

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed browser-automation wrapper with real-action and credential-handling risks, but its behavior is coherent with its purpose and includes clear scoping warnings.

Install only if you are comfortable running an external browser-automation CLI that can act on live websites and spend model-provider tokens. Use a virtual environment, pin or verify the webwright source before installing, keep outputs inside the workspace, and provide credentials only by environment variable names or a user-controlled browser profile, not as literal task text.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
references/setup.md:5
Finding

Unpinned Mutable Source Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: references/setup.md, lines 5–12
Vulnerability Type: Supply-chain risk from an unpinned source dependency
Risk Level: Medium

Vulnerable Code

bash
Webwright is distributed from source (MIT, https://github.com/microsoft/webwright):

git clone https://github.com/microsoft/webwright
cd webwright
python3 -m venv .venv && source .venv/bin/activate   # recommended: isolate the install
pip install -e .
playwright install chromium

Technical Analysis

The setup procedure clones the mutable default branch of the declared Microsoft Webwright repository and installs it in editable mode without pinning a reviewed release or commit. It also provides no source-integrity verification and does not lock the transitive Python dependencies resolved during installation.

Although the repository URL is consistent with the Skill's declared upstream project and no malicious package or typosquatted source was identified, the effective code installed by this procedure can change after the Skill itself has been reviewed. A compromised upstream repository, malicious default-branch update, or dependency compromise could therefore introduce executable code that was not present during this audit.

A virtual environment limits dependency conflicts but does not create a security boundary. Installation hooks and the installed CLI execute with the invoking user's operating-system privileges.

Attack Path

  1. The upstream repository's default branch, release process, or dependency metadata is compromised or receives a malicious change.
  2. A user follows the documented setup procedure at a later time.
  3. git clone retrieves the then-current, unreviewed default-branch contents.
  4. pip install -e . processes and installs that mutable source and its dependencies.
  5. Malicious installation logic may execute during installation, or malicious runtime logic may execute when webwright doctor or webwright main is invoked.

...[truncated 732 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin Webwright to a reviewed release tag and, preferably, verify the corresponding full commit SHA before installation.
  2. Publish the exact supported version in the setup guide rather than cloning the mutable default branch.
  3. Use a non-editable installation for normal use, reserving pip install -e . for development environments.
  4. Verify release artifacts or source archives with trusted checksums or signatures.
  5. Lock direct and transitive Python dependencies with hashes, and install them using hash enforcement where supported.
  6. Document a controlled upgrade process requiring review and testing before changing the pinned Webwright revision.
  7. Continue using an isolated virtual environment and run browser automation under a non-privileged account with access limited to the required workspace and credentials.
Vulnerability Patterns
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 60)May include surrounding context.

md
webwright in a venv, activate it (or prepend its `bin` to `PATH`) before
   running — otherwise generated scripts can pick up a different system Python
   that lacks the browser. See `references/setup.md`.
5. Choose an output directory INSIDE the current workspace. Never write into
   `~/.openclaw`, `$OPENCLAW_STATE_DIR`, or any active OpenClaw state directory.

## Invocation

Static analysis

No suspicious patterns detected.