Back to skill

Security audit

OpenClaw Browser

Security checks for vulnerabilities and agentic risk

Overview

This is an instruction-only browser automation skill whose sensitive capabilities are disclosed and aligned with its purpose.

Install this only if you want agents to operate real websites through OpenClaw's managed browser. Prefer a dedicated or task-specific browser profile, and supervise any use of the user profile, especially for logged-in pages, forms, downloads, uploads, screenshots, request inspection, or account-changing actions.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill explicitly recommends using the `user` profile for tasks requiring the user's live signed-in browser state, but it does not clearly warn that actions in that profile may access private data or perform real account changes. Because this skill is specifically for real browser automation with clicks, typing, downloads, and tab control, using the user's session increases the risk of unintended data exposure or destructive actions if the agent acts too broadly or the task is ambiguous.

Static analysis

No suspicious patterns detected.