Back to skill

Security audit

Browser Automation

Security checks for vulnerabilities and agentic risk

Overview

The skill is purpose-aligned for controlling a real signed-in browser, but it relies on unpinned remote npm execution and gives broad authenticated browser-control capability without enough scoping guidance.

Review before installing. Use only with a browser profile and sites you are comfortable exposing to automation, avoid sensitive personal or enterprise accounts, and prefer a pinned, reviewed version of `browser-relay-cli` rather than floating `npx` commands.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:31
Finding

Unpinned Third-Party npm Package Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:31-41 and references/commands.md:6-9
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Medium

Vulnerable Code

SKILL.md:31-41:

markdown
### 1. Make sure the runtime is available

Use `npx`, not a local repo path, unless the user explicitly wants development mode.

Quick checks:

```bash
npx browser-relay-cli version
npx browser-relay-cli extension-path
text

The workflow subsequently starts the same unpinned package with:

```bash
npx browser-relay-cli relay-start

references/commands.md:6-9:

bash
npx browser-relay-cli version
npx browser-relay-cli extension-path
npx browser-relay-cli relay-start
npx browser-relay-cli status

Technical Analysis

The skill instructs the agent to execute browser-relay-cli through npx without specifying an exact package version. No lockfile, package integrity hash, controlled package mirror, or documented provenance-verification step is provided.

When the package is not already available locally, npx can retrieve the version currently resolved by the npm registry and execute its code with the privileges of the local user. Consequently, the effective executable may change after the skill has been reviewed. A compromised maintainer account, malicious package release, registry compromise, or unexpected upstream change could therefore introduce arbitrary behavior.

The exposure is especially significant because the package starts a local browser relay and supplies an unpacked extension intended to operate within an already authenticated Chrome or Chromium session. Package code executes outside the browser sandbox as the current user, while the associated extension may interact with authenticated tabs and visible page content.

This finding does not establish that the current browser-relay-cli package is malicious. The risk arises from executing an unpinned, externally resolved dependency without reproducible dependency co ...[truncated 1602 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin every invocation to a specific reviewed release, for example:

    bash
    npx --yes browser-relay-cli@X.Y.Z version
    npx --yes browser-relay-cli@X.Y.Z extension-path
    npx --yes browser-relay-cli@X.Y.Z relay-start
    npx --yes browser-relay-cli@X.Y.Z status
    
  2. Replace X.Y.Z only through a documented dependency-review process. Review package contents, dependency changes, lifecycle scripts, and extension permissions before approving an upgrade.

  3. Prefer a controlled installation with a committed lockfile and integrity metadata rather than resolving the package dynamically during each use.

  4. Verify npm package provenance, publisher identity, release signatures or attestations where available, and registry integrity before execution.

  5. Consider installing the approved package in a restricted environment and invoking that verified installation instead of allowing npx to fetch code on demand.

  6. Run the relay under a dedicated least-privileged account or sandbox. Limit access to sensitive files, environment variables, local services, and unrelated browser profiles.

  7. Inspect and verify the unpacked extension contents before loading them. Document the expected extension identifier, required permissions, and approved package checksum.

  8. Apply the same exact-version requirement consistently in both SKILL.md and references/commands.md so that the command catalog cannot reintroduce unpinned execution.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (35)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill says it is for controlling an already signed-in Chrome session but does not prominently warn that this can expose or act on private account data, cookies, messages, documents, and authenticated workflows. That omission increases the chance that users invoke the skill without informed consent about the sensitivity of the browser context and the possibility of unintended actions on personal or corporate accounts.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The skill repeatedly instructs users to run npx browser-relay-cli without pinning an exact package version. Because npx fetches the current package from the registry at execution time, a compromised maintainer account, malicious new release, or dependency-chain attack could cause arbitrary code execution on the local machine with access to the user's browser context.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

This command uses an unpinned npx package invocation, which implicitly trusts the latest published version of browser-relay-cli. If the npm package or one of its installation-time dependencies is hijacked, running the documented command can execute attacker-controlled code and expose authenticated browser data.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

Starting the relay via an unpinned npx browser-relay-cli relay-start creates a supply-chain execution risk at the moment the tool is launched. In this skill's context, the tool then mediates control of a signed-in browser, so compromise could directly affect active authenticated sessions and private content.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The status-check command still relies on an unpinned remote package execution path. Even though it appears read-only, npx may install and run package code first, so the risk is arbitrary local code execution rather than merely incorrect status output.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The tab-listing command invokes an unpinned npm package, exposing users to supply-chain compromise. In this skill, the package is intended to interact with a real signed-in browser, which increases the sensitivity of any code executed through the tool.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

This example command references browser-relay-cli through floating npx, so users may execute whatever version is latest on npm at the time. A malicious release could abuse the browser relay permissions to inspect or manipulate authenticated tabs and local data.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

Opening a tab through an unpinned npx package still entails first downloading and executing package code from npm. The danger is amplified by the tool's purpose: controlling a real browser session where compromise can lead to account actions, data exposure, or session abuse.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

This click example continues the unpinned npx pattern, creating a supply-chain code execution path. Because the skill is specifically for browser interaction, exploitation could let malicious code drive user sessions, capture visible content, or abuse authenticated workflows.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

Typing into a page via a floating npx package is dangerous because package code runs locally before the requested browser action. An attacker controlling the package release pipeline could alter actions, exfiltrate browser content, or execute arbitrary code on the host.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

Even for a simple keypress command, using unpinned npx delegates trust to the latest npm release at execution time. In a signed-in browser control workflow, that trust boundary is especially sensitive because compromise can affect private accounts and session data.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The scroll command is another instance of unpinned remote package execution. While the action itself is low risk, the package execution model is not; a malicious update could execute arbitrary code and leverage access to the browser relay environment.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

Using npx browser-relay-cli without a pinned version allows whatever package version is current in the registry at execution time to be fetched and run. That creates a supply-chain risk where a compromised upstream release, typo-squat, or unexpected breaking change could execute code on the host or alter browser-control behavior.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

This command invokes npx against an unpinned package name, so users may execute an unintended or newly published version of the CLI. In a browser relay tool, that risk is amplified because the package can interact with a signed-in browser session and local machine context.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

An unpinned npx reference means runtime behavior depends on the latest registry state rather than a reviewed artifact. If the package or dependency chain is compromised, arbitrary code could run before any browser relay action is performed.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

Because npx resolves packages dynamically, this example exposes consumers to supply-chain compromise and non-reproducible execution. A malicious or broken update could gain local code execution and access the active browser relay environment.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

This unpinned package execution is a true security concern because it normalizes fetching and running a remote CLI without constraining the version. Since the tool operates on real browser tabs, compromise could affect authenticated sessions, page content, and local user activity.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The example encourages execution of an unpinned remote package at runtime, which is susceptible to malicious upstream updates or dependency hijacking. Because this command creates tabs and drives a real browser, the consequences extend beyond a simple documentation issue.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

Running activate through an unpinned npx package creates the same supply-chain exposure as the other commands in this document. If the resolved package is compromised, it can run arbitrary local code and manipulate the user's live browser session.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

This documentation line relies on a dynamically resolved CLI package, making behavior non-deterministic and vulnerable to upstream compromise. In the context of browser navigation, that could be abused to redirect activity, capture session data, or perform unauthorized actions in signed-in contexts.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The click command is shown using an unpinned npx package, exposing users to unexpected or malicious code execution from package resolution. Given that the tool can act on authenticated web pages, compromise may directly translate to account-impacting clicks or data access.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

This hover example still fetches a remote CLI at runtime without version pinning, creating a reproducibility and supply-chain integrity problem. A compromised package could do far more than hover, including arbitrary local execution or session abuse.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The type command is particularly sensitive because it can inject text into forms in a live signed-in browser, and the unpinned npx invocation means an attacker-controlled package version could execute. This combination makes the issue more dangerous than a generic tooling example.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

An unpinned npx call for keyboard input automation leaves users exposed to arbitrary code from upstream package changes. Since the skill is intended to control real browsers, malicious updates could submit forms, trigger transactions, or alter page state beyond the documented key press.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

Even for a wait helper, the unpinned package reference is a true supply-chain vulnerability because the risk lies in package resolution, not the specific subcommand. Any compromised release could run code with the user's permissions before performing the wait action.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.