Back to skill

Security audit

OpenClaw浏览器自动化配置

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent browser-automation setup documentation, but it under-discloses high-impact exposure of a browser control port and remote browser credentials.

Review before installing. If you use this skill, bind CDP to 127.0.0.1 only, do not expose port 9222 to untrusted networks, avoid logging into sensitive accounts through a remote browser endpoint, prefer a pinned and verified container digest, and keep browserless or other provider tokens out of shared config where possible.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:18
Finding

Unauthenticated Chrome DevTools Protocol Exposed on All Host Interfaces

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 18
Vulnerability Type: Unrestricted network exposure of a privileged browser-control interface
Risk Level: High

Vulnerable Code

bash
docker run -d --name browser-auto -p 9222:9222 --shm-size=512m chromedp/headless-shell:latest

Technical Analysis

Docker's -p 9222:9222 syntax publishes container port 9222 on all host interfaces by default. The Chrome DevTools Protocol (CDP) endpoint provides extensive control over the browser, while this deployment adds neither authentication nor a network access restriction.

The later use of http://127.0.0.1:9222 for verification and OpenClaw configuration does not restrict the Docker port binding. Therefore, the service may remain reachable through other host interfaces unless an external firewall independently blocks it.

An attacker with network access to TCP port 9222 can enumerate debugging targets, obtain a DevTools WebSocket endpoint, attach to browser contexts, execute JavaScript, inspect pages, and manipulate browser sessions.

Attack Path

  1. A user runs the documented Docker command.
  2. Docker publishes port 9222 on every host interface.
  3. An attacker reaches the host over a local, cloud, or otherwise permitted network path.
  4. The attacker requests CDP discovery endpoints such as /json/version or /json.
  5. The endpoint returns a DevTools WebSocket URL.
  6. The attacker connects to that WebSocket and issues CDP commands.
  7. The attacker controls browser tabs, reads browser-visible data, executes JavaScript, and performs actions within active web sessions.

Impact Assessment

Successful exploitation grants remote control over the headless browser and its active browsing contexts. Depending on browser usage, this can expose page content, authentication state, session-bound application data, and actions available to logged-in users. The attacker may also use browser network acc ...[truncated 299 chars]

Remediation
View remediation

Remediation Suggestions

Bind the CDP port exclusively to loopback when OpenClaw runs on the same host:

bash
docker run -d \
  --name browser-auto \
  -p 127.0.0.1:9222:9222 \
  --shm-size=512m \
  chromedp/headless-shell@sha256:<verified-digest>

Additionally:

  • Do not expose CDP directly to public or untrusted networks.
  • For remote connectivity, use an authenticated VPN or SSH tunnel.
  • If a reverse proxy is necessary, require strong authentication and TLS.
  • Apply host and cloud firewall rules that permit only specifically authorized sources.
  • Run the container with least privilege, a read-only filesystem where practical, dropped Linux capabilities, and appropriate resource limits.
  • Verify exposure after deployment using interface and firewall inspection rather than relying only on the configured client URL.

T08 · Insecure Dependencies

Warning
Location
SKILL.md:15
Finding

Mutable Unpinned Container Image Creates a Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 15-18
Vulnerability Type: Unpinned third-party container dependency
Risk Level: Medium

Vulnerable Code

markdown
推荐使用 `chromedp/headless-shell`(轻量且保持会话):

```bash
docker run -d --name browser-auto -p 9222:9222 --shm-size=512m chromedp/headless-shell:latest
text

### Technical Analysis

The instructions execute `chromedp/headless-shell:latest`. The `latest` tag is mutable and does not identify immutable image content, so the same command may retrieve and execute different software at different times.

The documentation provides neither a reviewed version constraint nor a SHA-256 image digest. Consequently, later upstream changes, registry compromise, account compromise, or an unintended image replacement could alter the code executed by users without any corresponding change to this skill package.

### Attack Path

1. An upstream publisher changes the image referenced by `latest`, or the publishing account or registry is compromised.
2. A malicious or unexpectedly modified image is associated with that tag.
3. A user follows the documented command and Docker retrieves the current image for `chromedp/headless-shell:latest`.
4. Docker starts the changed image locally.
5. The image executes its supplied entry point with the container's granted network, filesystem, process, and shared-memory access.
6. Malicious behavior could occur while appearing to be the documented browser service.

### Impact Assessment

The exact impact depends on container privileges, mounts, network access, and runtime hardening. Within the documented command, a compromised image could manipulate browser behavior, inspect data available inside the container, communicate over accessible networks, and abuse the published service.

No host directory or Docker socket mount is documented, and the command does not explicitly request privileged mode. Therefore, direct host c
...[truncated 162 chars]
Remediation
View remediation

Remediation Suggestions

  • Replace latest with a reviewed, supported release and an immutable SHA-256 digest.
  • Record the expected image registry and full canonical image reference.
  • Verify image signatures or provenance where the publisher supports them.
  • Scan the selected image for known vulnerabilities before adoption.
  • Establish a controlled update process that reviews and tests each new digest.
  • Run the container with least privilege, including dropped capabilities, a non-root user where supported, filesystem restrictions, and narrowly scoped network access.
  • Document the approved digest directly in the skill so repeated installations are reproducible.

Example:

bash
docker run -d \
  --name browser-auto \
  -p 127.0.0.1:9222:9222 \
  --shm-size=512m \
  chromedp/headless-shell@sha256:<reviewed-and-verified-digest>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Rp1

Medium
Category
MCP Rug Pull
Confidence
75% confidence
Finding

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill instructs users to connect browser automation to a remote or third-party CDP endpoint and even embed an API token in the URL, but it does not warn that full browser session data, page contents, cookies, and automation actions may transit through infrastructure outside the user's control. In this context, browser automation has high access to sensitive web content, so omission of privacy and credential-handling guidance materially increases the risk of token leakage, session compromise, and exposure of browsing data.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

A language-specific skill document can violate organizational language/locale policy when it forces a single language without user opt-in or justification. Here, all instructions and headings are Chinese-only, and there is no indication that the skill is region-specific or that alternative language support is available.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest description is written only in Chinese ("OpenClaw远程浏览器自动化配置"), which imposes a language choice in natural-language metadata without indicating user choice or opt-in. The policy requires avoiding language or locale constraints unless they are optional or clearly justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.