Back to skill

Security audit

opencli

Security checks for vulnerabilities and agentic risk

Overview

This skill openly documents powerful OpenCLI automation, but its broad website-data framing under-discloses authenticated account access, desktop app control, messaging, posting, deletion, and unverified install components.

Review before installing. Use only in a dedicated browser profile with only the accounts needed, verify the exact npm package and Browser Bridge extension source, avoid running the install with elevated privileges, and require explicit human confirmation before any private read, message, post, purchase-related action, write, or deletion.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:8
Finding

Unpinned Global Installation of a Third-Party npm Package

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
SKILL.md:9
Finding

Unverified Browser Bridge Is Granted Access to Authenticated Browser Sessions

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:2
Finding

Broad Trigger Scope Exposes Sensitive Read and State-Changing Operations Without Mandatory Consent Gates

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (10)

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill is presented as a website-data-fetching tool, but the command set includes many actions that send messages, post content, modify accounts, control desktop apps, and perform purchases or downloads. This mismatch can cause unsafe invocation and user consent failures because operators may grant or trigger capabilities far broader than the description suggests.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger phrases include many generic platform names and common terms such as twitter, reddit, youtube, and social media, which are likely to appear in ordinary conversation. This raises the risk of accidental activation of a high-privilege skill with access to logged-in sessions and state-changing commands.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill explicitly says it reuses Chrome login state, which can expose personal messages, saved items, notifications, private feeds, and other sensitive account data across many services. Failing to warn about the privacy and security implications of session reuse makes the skill especially dangerous because users may treat it like a public-data scraper when it actually acts with their authenticated identity.

Content

No source excerpt is available for this finding.

Memory Manipulation

High
Category
Memory Poisoning
Confidence
81% confidence
Finding

The command to start a new conversation and clear context enables manipulation of another AI tool's memory/state, which can remove prior safeguards, audit trail, or user-provided constraints before subsequent actions. In combination with send/read/model-switching features, this can be used to steer or sanitize downstream agent behavior in ways the user did not intend.

Content

Scanner excerpt · SKILL.md (reported line 50)May include surrounding context.

md
| `dump` | Dump the DOM to help AI understand the UI | - |
| `extract-code` | Extract multi-line code blocks from the current Antigravity conversation | - |
| `model` | Switch the active LLM model in Antigravity | `name` |
| `new` | Start a new conversation / clear context in Antigravity | - |
| `read` | Read the latest chat messages from Antigravity AI | `last` |
| `send` | Send a message to Antigravity AI via the internal Lexical editor | `message` |
| `serve` | - | - |

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill documents many commands that can send messages, post content, comment, follow, subscribe, like, delete, export, write, and manipulate external accounts, but it does not prominently warn users about these side effects. In a session-reusing automation context, omission of these warnings undermines informed consent and increases the chance of unauthorized or accidental account activity.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

This section exposes broad control over local desktop AI/chat applications, including reading chats, sending prompts, exporting conversations, switching models, and manipulating UI state. In a skill advertised for fetching website data, these capabilities materially expand the attack surface to local data exfiltration, prompt injection relay, and unauthorized actions in other applications.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The documented commands include account mutations and transactional actions such as sending messages, posting, following, liking, bookmarking, subscribing, adding items to cart, and deleting content. Because the skill reuses logged-in browser sessions, these actions could execute against real user accounts with little friction, making accidental or malicious misuse highly impactful.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The top-level framing says the skill fetches website data, but the detailed command list advertises extensive automation, writing, account manipulation, and app control. That contradiction increases the likelihood of unsafe use because reviewers and users may underestimate the real permissions and consequences.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

Most of the natural-language instructions and command descriptions are in Chinese, while some command text is in English, and the file does not indicate that Chinese is an optional or region-specific setting. This can amount to a language-policy issue because the skill implicitly forces a specific language without user opt-in or a documented justification.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The trigger documentation lists keywords but does not define boundaries for when the skill should or should not activate. Without negative examples or intent requirements, the skill may engage during unrelated discussion and expose sensitive session-backed capabilities unexpectedly.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.