Back to skill

Security audit

Browserbase Persist with captcha

Security checks for vulnerabilities and agentic risk

Overview

The skill fits its Browserbase automation purpose, but it exposes active session secrets and cookies in normal output and records authenticated sessions by default.

Install only if you are comfortable giving the agent control over Browserbase sessions that may stay logged in to websites. Avoid using it with sensitive accounts unless you disable recording, use separate contexts per site, delete contexts when finished, and avoid running get-cookies or live-url unless you intend to handle their output like credentials.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/browserbase_manager.py:376
Finding

Authentication-Bearing Browser Connection Data Is Exposed Through Standard Output

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/browserbase_manager.py:658
Finding

Complete Authentication Cookies Are Printed to Standard Output

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/browserbase_manager.py:343
Finding

Authenticated Browser Sessions Are Remotely Recorded and Logged by Default

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/requirements.txt:1
Finding

Third-Party Dependencies Are Not Reproducibly Pinned

Content
View full analysis
=1.0.0 playwright>=1.40.0 ``` ### Technical Analysis Both dependencies use lower-bound-only constraints. A future installation can therefore resolve to versions that were not present during this audit, including future major releases with incompatible behavior or compromised releases published under the legitimate package names. The installation instructions direct users to run `pip install -r requirements.txt`, causing package installation and later package imports to execute with the privileges of the invoking user. The Playwright setup also downloads a browser binary. Without exact version pins, hashes, or a lockfile, the effective installed code is not reproducible and can change after Skill review. No evidence was found that the listed package names are typosquatted or currently malicious. The risk arises from accepting uncontrolled future releases and lacking artifact integrity verification. ### Attack Path 1. A user follows the documented installation command at a later date. 2. The package resolver selects newer releases satisfying the broad `>=` constraints. 3. A selected release has been compromised, contains a malicious build artifact, or introduces unsafe incompatible behavior. 4. The package executes installation or import-time code with the user's privileges. 5. The malicious or vulnerable dependency can access environment variables, including Browserbase credentials, and any files available to the invoking user. ### Impact Assessment A compromised dependency could execute arbitrary Python code with the privileges of the user installing or running the Skill. This could expose Browserbase credentials, browser session data, local files, and other environment secrets. The practical scope depends on the privileges o ...[truncated 139 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
Findings (20)

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · references/api-quick-ref.md (reported line 53)May include surrounding context.

md
`POST /v1/contexts` with `{"projectId": "<project-id>"}`
Returns object with `id`.

### Delete Context
`DELETE /v1/contexts/{id}` → 204 No Content (permanent)

### Session Logs

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/api-quick-ref.md (reported line 54)May include surrounding context.

md
Returns object with `id`.

### Delete Context
`DELETE /v1/contexts/{id}` → 204 No Content (permanent)

### Session Logs
`GET /v1/sessions/{id}/logs` → Array of log entries (timestamps, methods, params)

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · scripts/browserbase_manager.py (reported line 289)May include surrounding context.

python
"message": "Context deleted permanently."
            })
        else:
            output_error(f"Failed to delete context (HTTP {e.code}): {body}")
            sys.exit(1)
    except Exception as e:
        output_error(f"Failed to delete context: {e}")

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · scripts/browserbase_manager.py (reported line 292)May include surrounding context.

python
"message": "Context deleted permanently."
            })
        else:
            output_error(f"Failed to delete context (HTTP {e.code}): {body}")
            sys.exit(1)
    except Exception as e:
        output_error(f"Failed to delete context: {e}")

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The get-cookies command emits the full browser cookie jar, which can include active session and authentication cookies, directly to stdout with no consent prompt, masking, or scope restriction. In the context of a persistent authenticated cloud browser tool, this enables straightforward credential/session theft and downstream account takeover if the output is logged, copied, or exposed to another tool or user.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
90% confidence
Finding

Session persistence is a real security concern here because the feature explicitly preserves authentication state across cloud browser sessions. While this appears to be core product functionality rather than malicious behavior, the skill context makes it more dangerous because it is built for long-lived authenticated automation, so leaked or mishandled contexts could grant continued access to protected accounts.

Content

Scanner excerpt · README.md (reported line 11)May include surrounding context.

md
This skill gives the OpenClaw agent the ability to:

- **Create cloud browser sessions** via Browserbase's infrastructure
- **Persist authentication** across sessions using Contexts (cookies, local storage,
  session storage are saved and restored automatically)
- **Solve CAPTCHAs automatically** — login flows and protected pages work without

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README promotes persistent authentication by saving and restoring cookies, local storage, and session storage across sessions without clearly warning about credential persistence and session hijacking risk. Because this skill is intended to maintain logged-in cloud browser sessions, retained auth artifacts could expose accounts or sensitive enterprise resources if contexts are reused, shared, or insufficiently protected.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README states that every browser session is recorded by default, but it does not clearly warn that recordings may capture sensitive data such as credentials, personal data, internal applications, and authenticated workflows. In the context of a browser automation skill specifically designed for persistent authenticated sessions, default recording materially increases privacy and data-retention risk if users do not explicitly opt in.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill documents capabilities that involve environment variables, package installation, network access, file output, and browser/session management, but it does not declare any explicit tool scope or permissions boundary. In an agent ecosystem, this increases the chance of over-broad execution and makes it harder to enforce least privilege or review what the skill is allowed to do.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
82% confidence
Finding

Persistent browser sessions are a risky capability because they retain authenticated state across runs, enabling access to protected resources without reauthentication. In this skill, that risk is amplified by the stated use cases of scraping authenticated pages and maintaining long-lived logged-in sessions, which can expose sensitive accounts or data if the session context is mishandled.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: browserbase-sessions
description: Create and manage persistent Browserbase cloud browser sessions with authentication persistence. Use when the user needs to automate browsers, maintain logged-in sessions across interactions, scrape authenticated pages, or manage cloud browser instances. Handles session creation, context-based auth persistence, keep-alive reconnection, captcha solving, session recording, screenshots, and session cleanup.
license: MIT
metadata:
  author: custom

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill promotes authentication persistence and reuse of cookies/local storage across interactions, but it does not provide a clear upfront warning that logged-in state and session artifacts will be retained. This can lead users to unintentionally preserve sensitive authenticated sessions, increasing the risk of account misuse, data leakage, or cross-task access if contexts are reused improperly.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill promotes authentication persistence and reuse of cookies/local storage across interactions, but it does not provide a clear upfront warning that logged-in state and session artifacts will be retained. This can lead users to unintentionally preserve sensitive authenticated sessions, increasing the risk of account misuse, data leakage, or cross-task access if contexts are reused improperly.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documentation explicitly promotes persistent authentication contexts, downloadable session recordings, logs, and downloaded-file archives, but it does not warn that these artifacts can contain active session cookies, tokens, page contents, sensitive form data, or other private user material. In a browser automation skill centered on maintaining logged-in sessions, omission of retention, access-control, and sensitivity guidance materially increases the risk of credential leakage and privacy exposure.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/browserbase_manager.py (reported line 13)May include surrounding context.

python
Commands:
    setup               Validate credentials and run a smoke test
    create-context      Create a new persistent context
    delete-context      Delete a context
    create-session      Create a new browser session
    list-sessions       List all sessions

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-quick-ref.md (reported line 5)May include surrounding context.

md
context_id = _resolve_context(args.context_id)
    api_key = get_env("BROWSERBASE_API_KEY")
    url = f"https://api.browserbase.com/v1/contexts/{context_id}"

    req = urllib.request.Request(url, method="DELETE", headers={
        "X-BB-API-Key": api_key,

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/browserbase_manager.py (reported line 263)May include surrounding context.

python
context_id = _resolve_context(args.context_id)
    api_key = get_env("BROWSERBASE_API_KEY")
    url = f"https://api.browserbase.com/v1/contexts/{context_id}"

    req = urllib.request.Request(url, method="DELETE", headers={
        "X-BB-API-Key": api_key,

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The execute-js command runs arbitrary JavaScript in the context of an authenticated browser session and returns results without any warning, policy gate, or domain restriction. In this skill, that can be used to perform privileged actions on behalf of a logged-in user, extract page data, or manipulate state across persistent sessions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The README enables automatic CAPTCHA solving by default without cautioning that this may interact with anti-bot protections and protected login flows in ways that violate site policies or bypass intended friction controls. In an automation skill for authenticated browsing, default CAPTCHA solving lowers barriers to automated access and can increase the chance of misuse or policy-violating behavior.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
94% confidence
Finding

The dependency specification uses a lower-bound only constraint (browserbase>=1.0.0), which allows installation of any future major or minor release. That can pull in vulnerable, compromised, or behavior-changing versions through normal installs, reducing build reproducibility and increasing supply-chain risk. In a browser automation skill that manages persistent authenticated sessions, a compromised dependency could expose session tokens, browser contents, or credentials.

Content

Scanner excerpt · scripts/requirements.txt (reported line 1)May include surrounding context.

text
browserbase>=1.0.0
playwright>=1.40.0

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

The requirement playwright>=1.40.0 is not pinned, so future releases are implicitly trusted at install time. This creates supply-chain and reproducibility risk, and in this skill's context Playwright has privileged access to browser sessions, authenticated pages, screenshots, and automation flows, so a malicious or flawed upstream version could materially increase exposure.

Content

Scanner excerpt · scripts/requirements.txt (reported line 2)May include surrounding context.

text
browserbase>=1.0.0
playwright>=1.40.0

Static analysis

No suspicious patterns detected.