T09 · Insecure Skill Coding Practices
- Location
scripts/browserbase_manager.py:376- Finding
Authentication-Bearing Browser Connection Data Is Exposed Through Standard Output
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill fits its Browserbase automation purpose, but it exposes active session secrets and cookies in normal output and records authenticated sessions by default.
Install only if you are comfortable giving the agent control over Browserbase sessions that may stay logged in to websites. Avoid using it with sensitive accounts unless you disable recording, use separate contexts per site, delete contexts when finished, and avoid running get-cookies or live-url unless you intend to handle their output like credentials.
scripts/browserbase_manager.py:376Authentication-Bearing Browser Connection Data Is Exposed Through Standard Output
scripts/browserbase_manager.py:658Complete Authentication Cookies Are Printed to Standard Output
scripts/browserbase_manager.py:343Authenticated Browser Sessions Are Remotely Recorded and Logged by Default
scripts/requirements.txt:1Third-Party Dependencies Are Not Reproducibly Pinned
Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.
`POST /v1/contexts` with `{"projectId": "<project-id>"}`
Returns object with `id`.
### Delete Context
`DELETE /v1/contexts/{id}` → 204 No Content (permanent)
### Session Logs
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
Returns object with `id`.
### Delete Context
`DELETE /v1/contexts/{id}` → 204 No Content (permanent)
### Session Logs
`GET /v1/sessions/{id}/logs` → Array of log entries (timestamps, methods, params)
Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.
"message": "Context deleted permanently."
})
else:
output_error(f"Failed to delete context (HTTP {e.code}): {body}")
sys.exit(1)
except Exception as e:
output_error(f"Failed to delete context: {e}")
Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.
"message": "Context deleted permanently."
})
else:
output_error(f"Failed to delete context (HTTP {e.code}): {body}")
sys.exit(1)
except Exception as e:
output_error(f"Failed to delete context: {e}")
The get-cookies command emits the full browser cookie jar, which can include active session and authentication cookies, directly to stdout with no consent prompt, masking, or scope restriction. In the context of a persistent authenticated cloud browser tool, this enables straightforward credential/session theft and downstream account takeover if the output is logged, copied, or exposed to another tool or user.
Session persistence is a real security concern here because the feature explicitly preserves authentication state across cloud browser sessions. While this appears to be core product functionality rather than malicious behavior, the skill context makes it more dangerous because it is built for long-lived authenticated automation, so leaked or mishandled contexts could grant continued access to protected accounts.
This skill gives the OpenClaw agent the ability to:
- **Create cloud browser sessions** via Browserbase's infrastructure
- **Persist authentication** across sessions using Contexts (cookies, local storage,
session storage are saved and restored automatically)
- **Solve CAPTCHAs automatically** — login flows and protected pages work without
The README promotes persistent authentication by saving and restoring cookies, local storage, and session storage across sessions without clearly warning about credential persistence and session hijacking risk. Because this skill is intended to maintain logged-in cloud browser sessions, retained auth artifacts could expose accounts or sensitive enterprise resources if contexts are reused, shared, or insufficiently protected.
The README states that every browser session is recorded by default, but it does not clearly warn that recordings may capture sensitive data such as credentials, personal data, internal applications, and authenticated workflows. In the context of a browser automation skill specifically designed for persistent authenticated sessions, default recording materially increases privacy and data-retention risk if users do not explicitly opt in.
The skill documents capabilities that involve environment variables, package installation, network access, file output, and browser/session management, but it does not declare any explicit tool scope or permissions boundary. In an agent ecosystem, this increases the chance of over-broad execution and makes it harder to enforce least privilege or review what the skill is allowed to do.
Persistent browser sessions are a risky capability because they retain authenticated state across runs, enabling access to protected resources without reauthentication. In this skill, that risk is amplified by the stated use cases of scraping authenticated pages and maintaining long-lived logged-in sessions, which can expose sensitive accounts or data if the session context is mishandled.
---
name: browserbase-sessions
description: Create and manage persistent Browserbase cloud browser sessions with authentication persistence. Use when the user needs to automate browsers, maintain logged-in sessions across interactions, scrape authenticated pages, or manage cloud browser instances. Handles session creation, context-based auth persistence, keep-alive reconnection, captcha solving, session recording, screenshots, and session cleanup.
license: MIT
metadata:
author: custom
The skill promotes authentication persistence and reuse of cookies/local storage across interactions, but it does not provide a clear upfront warning that logged-in state and session artifacts will be retained. This can lead users to unintentionally preserve sensitive authenticated sessions, increasing the risk of account misuse, data leakage, or cross-task access if contexts are reused improperly.
The skill promotes authentication persistence and reuse of cookies/local storage across interactions, but it does not provide a clear upfront warning that logged-in state and session artifacts will be retained. This can lead users to unintentionally preserve sensitive authenticated sessions, increasing the risk of account misuse, data leakage, or cross-task access if contexts are reused improperly.
The documentation explicitly promotes persistent authentication contexts, downloadable session recordings, logs, and downloaded-file archives, but it does not warn that these artifacts can contain active session cookies, tokens, page contents, sensitive form data, or other private user material. In a browser automation skill centered on maintaining logged-in sessions, omission of retention, access-control, and sensitivity guidance materially increases the risk of credential leakage and privacy exposure.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
Commands:
setup Validate credentials and run a smoke test
create-context Create a new persistent context
delete-context Delete a context
create-session Create a new browser session
list-sessions List all sessions
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
context_id = _resolve_context(args.context_id)
api_key = get_env("BROWSERBASE_API_KEY")
url = f"https://api.browserbase.com/v1/contexts/{context_id}"
req = urllib.request.Request(url, method="DELETE", headers={
"X-BB-API-Key": api_key,
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
context_id = _resolve_context(args.context_id)
api_key = get_env("BROWSERBASE_API_KEY")
url = f"https://api.browserbase.com/v1/contexts/{context_id}"
req = urllib.request.Request(url, method="DELETE", headers={
"X-BB-API-Key": api_key,
The execute-js command runs arbitrary JavaScript in the context of an authenticated browser session and returns results without any warning, policy gate, or domain restriction. In this skill, that can be used to perform privileged actions on behalf of a logged-in user, extract page data, or manipulate state across persistent sessions.
The README enables automatic CAPTCHA solving by default without cautioning that this may interact with anti-bot protections and protected login flows in ways that violate site policies or bypass intended friction controls. In an automation skill for authenticated browsing, default CAPTCHA solving lowers barriers to automated access and can increase the chance of misuse or policy-violating behavior.
The dependency specification uses a lower-bound only constraint (browserbase>=1.0.0), which allows installation of any future major or minor release. That can pull in vulnerable, compromised, or behavior-changing versions through normal installs, reducing build reproducibility and increasing supply-chain risk. In a browser automation skill that manages persistent authenticated sessions, a compromised dependency could expose session tokens, browser contents, or credentials.
browserbase>=1.0.0
playwright>=1.40.0
The requirement playwright>=1.40.0 is not pinned, so future releases are implicitly trusted at install time. This creates supply-chain and reproducibility risk, and in this skill's context Playwright has privileged access to browser sessions, authenticated pages, screenshots, and automation flows, so a malicious or flawed upstream version could materially increase exposure.
browserbase>=1.0.0
playwright>=1.40.0
No suspicious patterns detected.