Back to skill

Security audit

google-search-wsl

Security checks for vulnerabilities and agentic risk

Overview

This skill has a coherent web-search purpose, but it starts a Chrome debugging browser with overly broad local control access that users should review before installing.

Review this skill before installing if you share the machine or run untrusted local processes. Use a dedicated throwaway Chrome profile, avoid signing into sensitive accounts in the debug browser, change or restrict the debugging port/origins where possible, and close the Chrome process after searches are complete. Also consider overriding the default zh-CN language if that is not the search locale you want.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/google-search-chrome.sh:50
Finding

Wildcard Origin Authorization Exposes the Chrome DevTools Protocol

Content
View full analysis

Vulnerability Details

File Location: scripts/google-search-chrome.sh:50-55 and SKILL.md:28-34
Vulnerability Type: Unrestricted Chrome DevTools Protocol origin authorization
Risk Level: Medium

Vulnerable Code

scripts/google-search-chrome.sh:50-55:

bash
"$CHROME_BIN" \
    --remote-debugging-port="$PORT" \
    --remote-allow-origins='*' \
    --user-data-dir="$DATA_DIR" \
    --lang="${GOOGLE_SEARCH_LANG:-zh-CN}" \
    "${WSL_FLAGS[@]}" \

SKILL.md:28-34:

bash
google-chrome-stable --remote-debugging-port=9222 \
  --remote-allow-origins='*' \
  --user-data-dir="$HOME/.openclaw/chrome-debug-profile" \
  --lang=zh-CN \
  --disable-gpu \
  --disable-dev-shm-usage &

Technical Analysis

The --remote-allow-origins='*' argument disables Chrome DevTools WebSocket origin restrictions for all origins. Chrome DevTools Protocol clients that can reach the debugging port may consequently establish an unauthenticated control channel without being restricted to explicitly trusted origins.

A CDP client can enumerate and control browser targets, navigate tabs, execute JavaScript in page contexts, inspect page content, and interact with browser sessions. The script uses a dedicated profile, which reduces exposure to the user's normal browser profile, but searches, authentication state, cookies, and other content created within the debug profile remain exposed.

The script does not explicitly configure an external debugging address, and its health checks use 127.0.0.1; therefore, exposure is generally limited to clients capable of reaching the local CDP endpoint. The wildcard origin configuration nevertheless unnecessarily weakens CDP access control and increases the risk from malicious local processes or other clients able to connect to the port.

Attack Path

  1. The victim invokes the Skill, starting Chrome with remote debugging enabled on the configured port, which defaults to 9222.
  2. Chrome accepts CDP WebSocket ori ...[truncated 1188 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove --remote-allow-origins='*' from both the startup script and the manual command in SKILL.md.
  2. Explicitly bind the debugging service to loopback:
bash
--remote-debugging-address=127.0.0.1
  1. If an origin exception is operationally required, authorize only the exact trusted origin rather than using a wildcard.
  2. Prefer a randomly selected or ephemeral debugging port and communicate it only to the trusted browser-control component.
  3. Preserve the dedicated browser profile and ensure it is not reused for unrelated or sensitive browsing.
  4. Terminate the debugging browser when the search operation is complete to minimize the period during which CDP is available.
  5. Consider verifying that the detected endpoint belongs to the process launched by this script rather than treating any service responding on the configured port as the expected Chrome instance.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill description is framed with broad, common-use phrases like 'information retrieval' and 'web research,' which can match many ordinary user requests and cause the skill to activate unexpectedly. Over-broad activation increases the chance the agent will launch a browser and perform external web actions when the user did not explicitly intend to use this skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manual startup command hard-codes '--lang=zh-CN', forcing a specific locale without user consent. This can alter search results, content language, and browser behavior in ways the user did not request, potentially reducing reliability, causing confusion, or biasing retrieved information.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/google-search-chrome.sh (reported line 43)May include surrounding context.

sh
if [[ -z "$CHROME_BIN" ]]; then
    echo "错误:未找到 Chrome/Chromium" >&2
    echo "安装:sudo apt install google-chrome-stable" >&2
    exit 1
fi

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script sets Chrome's language to zh-CN by default via the --lang flag. This is a natural-language policy concern because it imposes a specific locale unless the user already knows to override GOOGLE_SEARCH_LANG.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.