Back to skill

Security audit

Browser Automation (CDP)

Security checks for vulnerabilities and agentic risk

Overview

This is a real browser automation skill, but it gives broad control over the user's logged-in browser and includes under-scoped guidance around cookies, tabs, downloads, and forced browser restarts.

Install only if you are comfortable letting the agent control a browser session. Use an isolated automation profile, avoid your daily logged-in browser, do not let it read browser cookie databases, confirm before form submissions/downloads/account actions, and close or clean the automation profile when finished.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
cdp-automation.js:88
Finding

Overprivileged Control of the User's Authenticated Browser Session

Content
View full analysis
new Promise((resolve, reject) => { http.get(`http://127.0.0.1:${this.port}/json/list`, r => { let d = ''; r.on('data', c => d += c); r.on('end', () => { try { resolve(JSON.parse(d)); } catch(e) { reject(e); } }); }).on('error', reject); }); const tabs = await doHttp(); return tabs.map(t => ({ id: t.id, url: t.url, title: t.title, type: t.type })); } ``` Relevant arbitrary navigation and JavaScript execution code: ```javascript async goto(url) { if (!this._tabId) await this.newTab(url); await this._tabCmd('Page.navigate', { url }); await this._waitForLoad(); return this; } async eval(script, returnByValue = true) { const data = await this._tabCmd('Runtime.evaluate', { expression: script, returnByValue }); return data.result; } ``` Relevant automatic attachment to an existing authenticated tab: ```javascript async _ensureTab() { if (!this._tabId) { // Try to use an existing bilibili tab const tabs = await this.tabs(); const existing = tabs.find(t => t.url.includes('bilibili.com')); if (existin ...[truncated 3335 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:38
Finding

Destructive Forced Termination of All Microsoft Edge Processes

Content
View full analysis
Remediation
View remediation
` --user-data-dir="C:\OpenClawBrowser\Edge" ``` 3. If the ordinary browser must be restarted, instruct the user to save their work and close it normally. 4. Require explicit confirmation before any process-termination command is executed. 5. Detect whether Edge is running and report the condition rather than killing it automatically. 6. Avoid `/F` and `/T` unless graceful termination has failed and the user separately authorizes forced shutdown. 7. Verify that the chosen debugging port is free before starting the isolated browser. 8. Add cleanup guidance that closes only the automation-owned browser process rather than every process with the same executable name. ]]>
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (19)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 26)May include surrounding context.

md
↓ require('./cdp-automation.js')

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill suggests reading browser cookie storage directly from SQLite to obtain complete cookies, including material intentionally protected from page scripts such as HttpOnly cookies. That advice enables extraction of highly sensitive credential artifacts and can bypass normal browser security boundaries protecting session tokens.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

Suggesting direct access to browser storage files to obtain full cookies crosses from browser automation into credential extraction. In skill context, this is especially dangerous because it provides an avenue to recover raw session tokens from the user's local browser state, which could enable account hijacking well beyond the original automation task.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The examples demonstrate filling and submitting forms and logging into accounts on live sites without any warning about consent, real-world side effects, or transmission of personal/account data. In an automation skill, this can normalize unsafe use and lead users or downstream agents to perform unintended account actions, submit sensitive information, or interact with production systems without adequate safeguards.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The authenticated-area example mentions persistent Chrome profile state but does not clearly explain the security implications of retained session cookies and account context. In shared or repeated agent runs, persisted sessions can enable unintended account access, cross-task data leakage, or actions performed under the wrong identity.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The reference documents that downloads are automatically allowed and saved to disk without emphasizing consent, validation, or quarantine controls. In a browser automation skill with full network access, this can lead to silent persistence of untrusted files, accidental storage of sensitive content, or downstream execution/use of malicious downloads by later steps or users.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill documents use of a persistent Chrome profile where cookies and saved credentials remain across sessions, but does not present this as a strong privacy and security risk. In an automation context, persistence increases the chance of credential leakage, session hijacking, cross-task data exposure, and unintended reuse of authenticated state when visiting attacker-controlled or unrelated sites.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly states it operates through the user's already logged-in browser, but it does not clearly warn that this grants access to authenticated account data and session context. In a browser automation skill, that omission materially increases the chance of unintended access to private content or actions under the user's identity.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill normalizes use of an already logged-in browser session for account-specific access, which means the automation can read private authenticated content and potentially perform actions as the user. In this context, the danger is elevated because the whole design depends on inheriting the user's live session rather than using a constrained service account or scoped token.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The setup instructions include force-killing the user's Edge process tree, which can close active sessions, interrupt work, and risk data loss, yet no safety warning is provided. Because this is presented as a recommended path for using a daily browser profile, users may unknowingly terminate an in-use browser with sensitive tabs and unsaved state.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The Minimax workflow gives detailed instructions for navigating an authenticated account area and extracting plan and usage information from page text. Even if intended for legitimate troubleshooting, this is sensitive account data collection through a live session, and the step-by-step extraction guidance lowers the barrier to misuse.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The module connects to local CDP HTTP and WebSocket endpoints to control a user's already-running browser, which can expose page contents, session state, and browsing context. Although comments describe the mechanism, there is no user-facing prompt, warning, or visible disclosure in the code before establishing this control channel.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The eval method sends arbitrary JavaScript for execution in the context of the attached browser tab via Runtime.evaluate. Because this module attaches to the user’s existing browser session, any caller of the skill can potentially read page content, interact with authenticated applications, or exfiltrate sensitive data from whatever tab is attached, making the capability highly dangerous in this context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The click helper performs DOM selection and triggers clicks inside the user’s attached browser tab without any safety boundary or target verification. In a live session, this can submit forms, authorize transactions, change account settings, or trigger other state-changing actions on authenticated sites, especially when combined with the module’s tendency to attach to existing tabs.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The helper silently reuses any existing tab whose URL contains 'bilibili.com', regardless of the caller’s requested target or browser state. In a browser-automation skill attached to a user’s live browsing session, this can cause commands, script execution, screenshots, and clicks to run against an unrelated authenticated tab, violating user expectations and potentially exposing or modifying sensitive session data.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The setup instructions are written in Chinese while the rest of the file is in English, imposing a specific language without offering a user choice or documenting a region-specific reason. This is a natural-language locale policy issue because users are not given an opt-in or alternative language path.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The download example causes a file to be written to a local directory but does not prominently warn that browser automation will persist files on disk. This can surprise users, create privacy or storage-management issues, and increase risk if untrusted content is downloaded and later opened or processed.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

Natural-language guidance throughout the skill is effectively constrained to Chinese, including operational instructions and examples. Under the stated policy, forcing a specific language without user opt-in is a locale/language policy concern unless an explicit choice or justification is provided.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This is a manifest file, so vague-trigger checks apply. The phrase '查看 SKILL.md 了解平台踩坑经验' is broad and non-specific about what operational constraints, exclusions, or activation boundaries matter, which weakens clarity around when and how the skill should be used.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dynamic_code_execution, suspicious.install_untrusted_source

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
cdp-automation.js:141

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
setup.json:21