T08 · Insecure Dependencies
- Location
SKILL.md:8- Finding
Unpinned Global Installation of a Third-Party npm Package
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill openly documents powerful OpenCLI automation, but its broad website-data framing under-discloses authenticated account access, desktop app control, messaging, posting, deletion, and unverified install components.
Review before installing. Use only in a dedicated browser profile with only the accounts needed, verify the exact npm package and Browser Bridge extension source, avoid running the install with elevated privileges, and require explicit human confirmation before any private read, message, post, purchase-related action, write, or deletion.
SKILL.md:8Unpinned Global Installation of a Third-Party npm Package
SKILL.md:9Unverified Browser Bridge Is Granted Access to Authenticated Browser Sessions
SKILL.md:2Broad Trigger Scope Exposes Sensitive Read and State-Changing Operations Without Mandatory Consent Gates
The skill is presented as a website-data-fetching tool, but the command set includes many actions that send messages, post content, modify accounts, control desktop apps, and perform purchases or downloads. This mismatch can cause unsafe invocation and user consent failures because operators may grant or trigger capabilities far broader than the description suggests.
The trigger phrases include many generic platform names and common terms such as twitter, reddit, youtube, and social media, which are likely to appear in ordinary conversation. This raises the risk of accidental activation of a high-privilege skill with access to logged-in sessions and state-changing commands.
The skill explicitly says it reuses Chrome login state, which can expose personal messages, saved items, notifications, private feeds, and other sensitive account data across many services. Failing to warn about the privacy and security implications of session reuse makes the skill especially dangerous because users may treat it like a public-data scraper when it actually acts with their authenticated identity.
The command to start a new conversation and clear context enables manipulation of another AI tool's memory/state, which can remove prior safeguards, audit trail, or user-provided constraints before subsequent actions. In combination with send/read/model-switching features, this can be used to steer or sanitize downstream agent behavior in ways the user did not intend.
| `dump` | Dump the DOM to help AI understand the UI | - |
| `extract-code` | Extract multi-line code blocks from the current Antigravity conversation | - |
| `model` | Switch the active LLM model in Antigravity | `name` |
| `new` | Start a new conversation / clear context in Antigravity | - |
| `read` | Read the latest chat messages from Antigravity AI | `last` |
| `send` | Send a message to Antigravity AI via the internal Lexical editor | `message` |
| `serve` | - | - |
The skill documents many commands that can send messages, post content, comment, follow, subscribe, like, delete, export, write, and manipulate external accounts, but it does not prominently warn users about these side effects. In a session-reusing automation context, omission of these warnings undermines informed consent and increases the chance of unauthorized or accidental account activity.
This section exposes broad control over local desktop AI/chat applications, including reading chats, sending prompts, exporting conversations, switching models, and manipulating UI state. In a skill advertised for fetching website data, these capabilities materially expand the attack surface to local data exfiltration, prompt injection relay, and unauthorized actions in other applications.
The documented commands include account mutations and transactional actions such as sending messages, posting, following, liking, bookmarking, subscribing, adding items to cart, and deleting content. Because the skill reuses logged-in browser sessions, these actions could execute against real user accounts with little friction, making accidental or malicious misuse highly impactful.
The top-level framing says the skill fetches website data, but the detailed command list advertises extensive automation, writing, account manipulation, and app control. That contradiction increases the likelihood of unsafe use because reviewers and users may underestimate the real permissions and consequences.
Most of the natural-language instructions and command descriptions are in Chinese, while some command text is in English, and the file does not indicate that Chinese is an optional or region-specific setting. This can amount to a language-policy issue because the skill implicitly forces a specific language without user opt-in or a documented justification.
The trigger documentation lists keywords but does not define boundaries for when the skill should or should not activate. Without negative examples or intent requirements, the skill may engage during unrelated discussion and expose sensitive session-backed capabilities unexpectedly.
No suspicious patterns detected.