Back to skill

Security audit

HTML-to-Selenium

Security checks for vulnerabilities and agentic risk

Overview

The skill is for webpage analysis, but it gives the browser and file-writing script broader authority than users may expect and can expose sensitive page HTML.

Install only if you will run it in an isolated environment on pages you are authorized to inspect. Do not use it on authenticated, internal, private, or sensitive pages unless you first add URL restrictions, safe temporary-file handling, TLS validation, browser sandboxing, and HTML redaction before any LLM submission.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (6)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/fetch_page.py:132
Finding

Unrestricted URL navigation permits access to local and internal resources

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/fetch_page.py:146
Finding

User-controlled output path can overwrite and delete arbitrary writable files

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:27
Finding

Workflow directs potentially sensitive page HTML to an unspecified LLM

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/fetch_page.py:123
Finding

Browser sandbox and TLS certificate validation are disabled

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:22
Finding

Unpinned Selenium installation creates supply-chain and reproducibility risk

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/fetch_page.py:164
Finding

Error handling persistently stores potentially sensitive page source

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill description promises broad Selenium automation and page analysis behavior, while the documented workflow mainly fetches page HTML and saves it locally. This mismatch is dangerous because users may trust the high-level description without realizing the concrete behavior includes local persistence of webpage source, which can capture secrets from authenticated pages and expand the skill's effective data-handling footprint.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill instructs users to fetch remote webpages and write the HTML to a local output file, but it does not declare any tool scope such as network or file-write permissions. This creates hidden capability risk: an agent or reviewer may underestimate that the skill can exfiltrate page content from remote sites into local storage, including sensitive tokens or authenticated content if misused.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The phraseology around analyzing 'any webpage' and handling generic automation tasks is overly broad and can encourage use against arbitrary targets, including authenticated, internal, or third-party services. In a skill that fetches page source and supports Selenium-based interaction, broad activation language lowers the barrier to misuse for scraping, unauthorized automation, or collection of sensitive HTML content.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The template explicitly instructs users to send downloaded HTML content to a large model but provides no warning about sensitive data that may be present in page source, such as CSRF tokens, hidden form values, internal URLs, user identifiers, or confidential business content. In the context of a skill designed to analyze arbitrary webpages and assist with login/form automation, this omission increases the likelihood of unintended data exfiltration to an external model service.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This Python file contains natural-language descriptions and user-facing output exclusively in Chinese, including the module docstring and command-line interface text. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The file includes a full Chinese section in addition to the English section, but it does not state whether language selection is user-driven or optional. Because SQP-3 covers language/locale policy violations, presenting a fixed additional locale without an explicit user choice can conflict with organizational expectations around language opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.