Back to skill

Security audit

Browser Setup (No-Root Linux)

Security checks for vulnerabilities and agentic risk

Overview

This skill appears to be a legitimate no-root Chrome installer for OpenClaw, but its install script runs downloaded browser code without independent integrity checks and can generate an unsafe persistent wrapper from unvalidated path arguments.

Review before installing. Use only on a machine where you are comfortable running a user-level Chrome installer, avoid passing custom --chrome-dir or --libs-dir values from untrusted input, and prefer a version that pins and verifies downloaded packages and safely quotes generated wrapper paths.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/install-browser.sh:120
Finding

Command Injection Through Unsafely Generated Chrome Wrapper

Content
View full analysis
Creating wrapper script..." cat > "$WRAPPER" << WEOF #!/bin/bash export LD_LIBRARY_PATH=${LIBS_DIR}/lib\${LD_LIBRARY_PATH:+:\$LD_LIBRARY_PATH} export FONTCONFIG_FILE=${FC_CONF} exec ${CHROME_BIN} "\$@" WEOF chmod +x "$WRAPPER" echo "==> Verifying Chrome..." VERSION=$("$WRAPPER" --version 2>/dev/null || echo "FAILED") echo " $VERSION" ``` ### Technical Analysis The `--chrome-dir` and `--libs-dir` arguments are accepted without validation and assigned to `CHROME_DIR` and `LIBS_DIR`. These values are subsequently expanded into an unquoted heredoc used to generate an executable shell script. Because the heredoc delimiter is unquoted, parameter expansion occurs while the wrapper is generated. More importantly, the expanded path values are inserted directly into shell source code without shell-safe serialization or runtime quoting. A path containing whitespace, command separators, shell operators, command substitutions, or newline characters can therefore change the syntax and behavior of the generated wrapper. The installer grants execute permission to the wrapper and immediately runs it for version verification. Consequently, injected commands can execute during installation rather than requiring a later browser launch. The malicious code also remains embedded in the generated wrapper and may execute again whenever OpenClaw launches Chrome. ### Attack Path 1. An attacker gains control over, or influences, the arguments passed to `install-browser.sh`. 2. The attacker supplies a crafted value through `--libs-dir` or ...[truncated 1063 chars]
Remediation
View remediation
"$WRAPPER" chmod 700 "$WRAPPER" ``` Additionally, reject unsafe path values before generating the wrapper: ```bash validate_path() { local value="$1" if [[ "$value" == *$'\n'* || "$value" == *$'\r'* ]]; then echo "ERROR: Path contains prohibited control characters" >&2 exit 1 fi } ``` ]]>

T03 · Remote Payload Retrieval and Execution

Warning
Location
scripts/install-browser.sh:27
Finding

Mutable Chrome Executable Downloaded and Executed Without Integrity Verification

Content
View full analysis
Downloading Google Chrome..." wget -q -O "$TMP_DIR/chrome.deb" \ https://dl.google.com/linux/direct/google-chrome-stable_current_amd64.deb echo "==> Extracting Chrome binary..." mkdir -p "$CHROME_DIR" dpkg-deb -x "$TMP_DIR/chrome.deb" "$CHROME_DIR" ``` The downloaded executable is subsequently launched through the generated wrapper: ```bash echo "==> Verifying Chrome..." VERSION=$("$WRAPPER" --version 2>/dev/null || echo "FAILED") echo " $VERSION" ``` ### Technical Analysis The installer retrieves `google-chrome-stable_current_amd64.deb`, a mutable package URL whose content can change after the Skill has been audited. It does not pin an expected Chrome version, verify a cryptographic digest, or authenticate the package using a pinned trusted signing key. HTTPS provides transport encryption and server authentication but does not establish a reproducible identity for the downloaded package. It does not protect against every relevant supply-chain scenario, such as upstream compromise, unexpected artifact replacement, a compromised trusted certificate authority, or a maliciously configured TLS-intercepting proxy. The package is extracted rather than installed through a package manager verification workflow. Its Chrome executable is then invoked through the wrapper during version verification. Therefore, the effective executable payload can change independently of the reviewed Skill source. ### Attack Path 1. The mutable artifact at the remote URL is replaced, or the download channel or trusted infrastructure is compromised. 2. The installer retrieves the substituted package without checking an expected digest or trusted package signature. 3. `dpkg-deb` extracts the package into the user's Chrome installation director ...[truncated 1012 chars]
Remediation
View remediation
_amd64.deb" printf '%s %s\n' "$EXPECTED_SHA256" "$TMP_DIR/chrome.deb" | sha256sum --check --status || { echo "ERROR: Chrome package integrity verification failed" >&2 exit 1 } dpkg-deb -x "$TMP_DIR/chrome.deb" "$CHROME_DIR" ``` The pinned digest must be obtained and maintained through a trusted release process independent of the package download itself. ]]>
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (3)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill clearly instructs users to run shell commands and a local install script, but it declares no explicit tool scope or allowed-tools metadata. That mismatch can cause the platform to under-enforce execution boundaries, increasing the risk that the skill can invoke shell actions without transparent permission signaling or proper review.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: browser-setup
description: "Install and configure headless Chrome for OpenClaw browser tool in environments without root/sudo access (cloud containers, VPS, sandboxed hosts). Use when: (1) browser tool fails with No supported browser found, (2) Chrome crashes with Page crashed or missing library errors, (3) setting up browser automation on a fresh server or container, (4) user asks to install or fix the browser for OpenClaw. NOT for macOS/Windows desktops with Chrome already installed, or Chrome extension relay setup."
---

# Browser Setup (No-Root Linux)

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/install-browser.sh (reported line 96)May include surrounding context.

sh
echo "    Installed $FONT_COUNT font files."

echo "==> Writing fontconfig..."
mkdir -p "$(dirname "$FC_CONF")"
cat > "$FC_CONF" << 'FCEOF'
<?xml version="1.0"?>
<!DOCTYPE fontconfig SYSTEM "fonts.dtd">

Static analysis

No suspicious patterns detected.