T09 · Insecure Skill Coding Practices
- Location
scripts/meal_subsidy.py:149- Finding
Chrome Is Launched Without Its Security Sandbox
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill appears purpose-built for meal-subsidy automation, but it can automatically submit HR claims through a remotely debuggable browser and stores sensitive work records locally without strong controls.
Review this before installing. Only run it in an isolated, trusted user account or disposable browser profile, avoid leaving Chrome remote debugging open, remove `--no-sandbox`, require confirmation before each HR submission, and clean or restrict access to generated screenshots, CSVs, logs, and browser profile data.
scripts/meal_subsidy.py:149Chrome Is Launched Without Its Security Sandbox
scripts/meal_subsidy.py:128Fixed Unauthenticated CDP Endpoint Exposes an Authenticated HR Browser Session
SKILL.md:36Third-Party Dependencies Are Installed Without Version or Integrity Pinning
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
date,off,cross,yuan
2026-04-28,21:33,False,20
The skill documentation describes capabilities that imply shell execution, network access, local file writes, and potential environment use, but it does not declare any tool scope or permissions boundary. This is dangerous because an automation skill that can launch browsers, connect to remote-debugging endpoints, access authenticated web sessions, and write local artifacts creates meaningful execution and data-handling risk without explicit user-visible constraints.
The skill description emphasizes convenience but does not clearly warn that it will automatically fill and submit forms on the user's behalf. In an HR workflow, silent or insufficiently disclosed submission behavior can cause unauthorized actions, mistaken claims, or compliance issues because users may assume the tool only checks eligibility rather than filing requests.
The documentation lists screenshots and CSV records that will be stored locally, but it does not present this as a clear privacy/security warning to the user. This is dangerous because attendance screenshots and application logs may contain sensitive employment data, and undisclosed local persistence increases the risk of data leakage, retention beyond need, or accidental sharing.
Suspicious Unicode normalization or mixed-script content
Code issues a request to a loopback, link-local, or private-range host. This can reach internal services not meant to be exposed and is a common SSRF pivot.
def get_cdp_url(port: int = None) -> Optional[str]:
if port is None: port = Config.CDP_PORT
try:
with urllib.request.urlopen(f"http://127.0.0.1:{port}/json/version", timeout=5) as r:
return json.loads(r.read()).get("webSocketDebuggerUrl")
except Exception as e:
log_d(f"CDP fail: {e}")
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
import subprocess
path = next((p for p in Config.CHROME_PATHS if p and os.path.exists(p)), None)
if not path: raise RuntimeError("Chrome not found")
subprocess.Popen(
[path, "--remote-debugging-port=9222",
f"--user-data-dir={Config.CHROME_DATA}",
"--no-sandbox", "--disable-dev-shm-usage", "--disable-gpu"],
The script automatically fills and submits HR reimbursement forms based on parsed attendance data with no final user confirmation step. In an agent-skill context, this can trigger unintended submissions, duplicate claims, or fraudulent-looking actions if the data is wrong, the page state changes, or the skill is invoked ambiguously.
The documentation says Chrome remote debugging is a one-time manual setup, but later states the script will automatically launch a new Chrome with a debugging port if unavailable. This mismatch is risky because remote-debugging startup changes the trust model: it may attach to or create an authenticated browser context with broader access than the user expects.
The stated purpose is HR meal-subsidy automation based on attendance records and automatic form submission. Automatically starting a new Chrome process is a broader host-control capability that is not clearly justified by the manifest's purpose statement, especially since the rest of the document frames login and browser startup as a manual prerequisite.
The code saves attendance screenshots, logs, and CSV files containing work schedule and overtime-related personal data to disk without explicit consent, minimization, or retention controls. In a shared workstation or agent environment, these artifacts can expose sensitive employee activity data to other local users or later processes.
No suspicious patterns detected.