T09 · Insecure Skill Coding Practices
- Location
scripts/google-search-chrome.sh:50- Finding
Wildcard Origin Authorization Exposes the Chrome DevTools Protocol
- Content
View full analysis
Vulnerability Details
File Location:
scripts/google-search-chrome.sh:50-55andSKILL.md:28-34
Vulnerability Type: Unrestricted Chrome DevTools Protocol origin authorization
Risk Level: MediumVulnerable Code
scripts/google-search-chrome.sh:50-55:bash "$CHROME_BIN" \ --remote-debugging-port="$PORT" \ --remote-allow-origins='*' \ --user-data-dir="$DATA_DIR" \ --lang="${GOOGLE_SEARCH_LANG:-zh-CN}" \ "${WSL_FLAGS[@]}" \SKILL.md:28-34:bash google-chrome-stable --remote-debugging-port=9222 \ --remote-allow-origins='*' \ --user-data-dir="$HOME/.openclaw/chrome-debug-profile" \ --lang=zh-CN \ --disable-gpu \ --disable-dev-shm-usage &Technical Analysis
The
--remote-allow-origins='*'argument disables Chrome DevTools WebSocket origin restrictions for all origins. Chrome DevTools Protocol clients that can reach the debugging port may consequently establish an unauthenticated control channel without being restricted to explicitly trusted origins.A CDP client can enumerate and control browser targets, navigate tabs, execute JavaScript in page contexts, inspect page content, and interact with browser sessions. The script uses a dedicated profile, which reduces exposure to the user's normal browser profile, but searches, authentication state, cookies, and other content created within the debug profile remain exposed.
The script does not explicitly configure an external debugging address, and its health checks use
127.0.0.1; therefore, exposure is generally limited to clients capable of reaching the local CDP endpoint. The wildcard origin configuration nevertheless unnecessarily weakens CDP access control and increases the risk from malicious local processes or other clients able to connect to the port.Attack Path
- The victim invokes the Skill, starting Chrome with remote debugging enabled on the configured port, which defaults to
9222. - Chrome accepts CDP WebSocket ori ...[truncated 1188 chars]
- The victim invokes the Skill, starting Chrome with remote debugging enabled on the configured port, which defaults to
- Remediation
View remediation
Remediation Suggestions
- Remove
--remote-allow-origins='*'from both the startup script and the manual command inSKILL.md. - Explicitly bind the debugging service to loopback:
bash --remote-debugging-address=127.0.0.1- If an origin exception is operationally required, authorize only the exact trusted origin rather than using a wildcard.
- Prefer a randomly selected or ephemeral debugging port and communicate it only to the trusted browser-control component.
- Preserve the dedicated browser profile and ensure it is not reused for unrelated or sensitive browsing.
- Terminate the debugging browser when the search operation is complete to minimize the period during which CDP is available.
- Consider verifying that the detected endpoint belongs to the process launched by this script rather than treating any service responding on the configured port as the expected Chrome instance.
- Remove
