Back to skill

Security audit

browser-automation-skills

Security checks across malware telemetry and agentic risk

Overview

This skill is legitimate browser automation, but it gives an agent broad control over an existing Chrome session without enough scoping or consent guidance for sensitive pages and actions.

Install only if you deliberately want an agent to control Chrome. Use a separate Chrome profile with no sensitive accounts, keep the debugging endpoint local, close private tabs first, review any screenshots or recordings before sharing them, and require explicit confirmation before login, form submission, purchases, posts, deletions, or account changes.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (17)

Lp3

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding
The skill describes capabilities that can control a local browser, access network resources, and likely interact with environment-dependent tooling, but it does not declare permissions or boundaries for those capabilities. This can cause users or orchestrators to invoke the skill without understanding that it can reach external sites and affect the local system, increasing the risk of unintended data exposure or unsafe automation.

Missing User Warnings

Medium
Confidence
84% confidence
Finding
The README prominently advertises capabilities to navigate, scrape, debug, and record a user's existing local Chrome session, but it does not warn that these actions can expose authenticated session data, page contents, cookies-derived access, or sensitive on-screen information. In the context of an AI skill intended for broad use by coding assistants, the lack of explicit privacy and consent guidance materially increases the chance of unsafe deployment or accidental over-collection.

Missing User Warnings

High
Confidence
95% confidence
Finding
The quick-start instructs users to launch Chrome with --remote-debugging-port=9222 and connect automation tooling to the existing browser, but it provides no warning that exposing the DevTools protocol can grant powerful control over the browser session. If the debugging port is reachable by other local or network actors, they may navigate pages, inspect content, exfiltrate data, or act within authenticated sessions, making this a significant security risk.

Vague Triggers

Medium
Confidence
82% confidence
Finding
Several skills are marked for automatic invocation with broad descriptions like navigation, interaction, scraping, and debugging, but there are no clear trigger constraints or consent boundaries. In an agent setting, this can lead to the model initiating browser actions, data extraction, or page interaction without sufficiently explicit user intent, especially on sensitive or authenticated pages.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The documentation states that the skill can control local Chrome and includes a lock feature that blocks user input via a visual overlay, but it does not provide a prominent warning about local system impact or operational risks. Because this affects the user's active browser and can interfere with input while operating inside real authenticated sessions, misuse could cause loss of control, unintended actions, or exposure of sensitive data.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The documentation advertises powerful inspection features such as DOM extraction, readable page conversion, network request listing, and console log capture, but it does not warn that these may expose sensitive data including tokens, session identifiers, PII, internal URLs, or page content from authenticated sessions. In a browser-automation skill controlling a local Chrome instance, this omission increases the chance that an agent will over-collect or disclose sensitive browsing data without user awareness or minimization.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
This script exposes powerful browser-inspection capabilities against an already logged-in, user-owned Chrome session, including full DOM extraction, visible text scraping, console capture, network logging, screenshots, navigation, typing, and clicks. In the context of an agent skill, that enables collection of sensitive page content, session-derived data, internal app information, and user-visible secrets without any explicit per-action consent, scope restriction, or redaction, making exfiltration and unauthorized interaction significantly easier.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill explicitly instructs an agent to control the local Chrome browser and, for the CLI backend, to lock input to prevent user interference, but it provides no user-facing consent, warning, or boundary on when such control is appropriate. In an agent setting, this can enable covert browser manipulation or temporary denial of user control over their own interface, which is especially risky because it targets a local interactive application rather than a sandboxed remote browser.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The documented ability to read browser network requests and console logs can expose sensitive data such as authentication tokens, internal URLs, request payloads, error traces, and session-related information. Because the skill is a general browser automation reference and does not warn about sensitive data handling or impose minimization rules, it increases the chance that an agent will collect and expose private browser-derived information unnecessarily.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The description uses broad trigger phrases like 'debug a website,' 'check for errors,' and 'troubleshoot web applications,' which can cause the skill to activate for many generic requests. In this skill's context, over-activation matters because the workflow can inspect network traffic, console logs, screenshots, and DOM content, increasing the chance of collecting sensitive data when a narrower tool would have sufficed.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill instructs the agent to capture and report URLs, network requests, console logs, screenshots, and DOM contents without warning that these artifacts may contain tokens, personal data, internal endpoints, or other secrets. Because the skill is specifically designed for deep page inspection, the absence of a sensitivity warning and minimization guidance materially increases the risk of unintended data exposure.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill description is very broad and covers a wide range of common browsing actions, including clicking, typing, logging in, and submitting forms, without strong activation boundaries or explicit authorization checks. In an agent setting with browser control, this can cause the skill to be invoked for sensitive workflows too easily, increasing the risk of unintended or unsafe interactions on arbitrary websites.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly supports login and form submission but provides no warning, restriction, or handling guidance for credentials, personal data, payment information, or other secrets. Because this skill controls a local browser and can type into web forms, the lack of safeguards makes credential entry, data exfiltration, or unintended submission of sensitive information materially more dangerous.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The skill description includes very broad trigger phrases such as 'open', 'go to', 'visit', 'browse', and any provided URL, which can cause the agent to invoke this skill in many ordinary contexts without strong disambiguation. In a browser-control skill, overbroad activation increases the chance of unintended navigation to attacker-influenced pages, potentially exposing local browser state, cookies, or causing follow-on unsafe actions through tool chaining.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The skill description contains very broad trigger phrases like 'extract information', 'read web content', and 'collect data from a website', which can match many ordinary browsing or summarization requests and cause this skill to activate more often than intended. In a browser-automation skill, over-triggering is risky because it can lead an agent to perform web scraping actions, collect external content, or save large datasets when a simpler, less privileged response would have been appropriate.

Natural-Language Policy Violations

Low
Confidence
76% confidence
Finding
The manifest includes Chinese trigger text by default without documenting language behavior, scope, or user opt-in. While not directly enabling code execution, undocumented multilingual triggers can broaden activation surface unexpectedly, causing the skill to be selected for users or deployments that did not intend Chinese-language matching and making routing behavior harder to audit.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The skill description uses very broad trigger phrases like 'see what a page looks like,' 'preview a website,' and generic screenshot/screen-capture terms, which can cause the skill to be invoked in situations beyond the user's specific intent. In a browser-automation skill with navigation capability, accidental invocation can lead to unintended page loads, screenshots of sensitive content, or unnecessary interaction with local browser state.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.