Back to skill

Security audit

AgentBrowser

Security checks for vulnerabilities and agentic risk

Overview

This looks like a legitimate browser automation skill, but it needs review because it documents saving and reusing authenticated browser sessions without clear secret-handling safeguards.

Install only if you are comfortable with a broad browser automation tool. Use a pinned reviewed version, avoid saving authenticated state unless necessary, keep any state, trace, screenshot, PDF, or video files out of repositories and shared folders, and use test or least-privileged accounts for automation.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:20
Finding

Unpinned Global Installation of a Third-Party Dependency

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:20-22; CONTRIBUTING.md:25
Vulnerability Type: Unpinned and mutable third-party dependency installation
Risk Level: Medium

Vulnerable Code

SKILL.md:20-22:

bash
npm install -g agent-browser
agent-browser install
agent-browser install --with-deps

CONTRIBUTING.md:25:

bash
npm install -g agent-browser@latest

Technical Analysis

The documented installation process globally installs agent-browser without pinning an exact reviewed version. The unversioned package specification resolves to the registry's current default release, while @latest explicitly resolves through a mutable distribution tag.

The project does not include a lockfile, package integrity hash, vendored implementation, or other mechanism that binds installation to the version reviewed during this audit. Because npm packages may contain lifecycle scripts and executable binaries, an altered or compromised future release could execute code under the privileges of the user performing the installation. A global installation also exposes the resulting executable across the user's environment rather than limiting it to this project.

No evidence was found that the current upstream package is malicious. The vulnerability is the unsafe, mutable dependency installation process.

Attack Path

  1. An attacker compromises the upstream npm package, its maintainer account, or the release pipeline.
  2. The attacker publishes a malicious release and assigns it to the registry's default or latest distribution tag.
  3. A user follows the Skill instructions and runs the unpinned global installation command.
  4. npm downloads the attacker-controlled package and may execute its lifecycle scripts during installation.
  5. The malicious package runs with the installing user's privileges and installs or replaces the globally accessible agent-browser executable.
  6. Subsequent br ...[truncated 697 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin agent-browser to an exact version that has been reviewed, for example:
    bash
    npm install --save-exact agent-browser@<reviewed-version>
    
  2. Prefer a project-local installation over a global installation, and invoke the dependency through an explicitly controlled project script or trusted package runner configuration.
  3. Commit a lockfile that records the complete dependency graph and integrity metadata.
  4. Document the expected npm registry and integrity hash for the reviewed package artifact.
  5. Remove the recommendation to install @latest; version upgrades should require explicit review and testing.
  6. Run installation with the least-privileged account available and do not use sudo or an administrative shell.
  7. Audit npm lifecycle scripts and transitive dependencies before approving each version update.
  8. Where practical, distribute a reproducibly built and cryptographically verified artifact.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:235
Finding

Authenticated Browser State Is Persisted Without Security Controls

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:235-236; SKILL.md:263-266
Vulnerability Type: Insecure handling of sensitive session-state files
Risk Level: Medium

Vulnerable Code

SKILL.md:235-236:

bash
agent-browser state save auth.json    # Save session state
agent-browser state load auth.json    # Load saved state

SKILL.md:263-266:

bash
agent-browser state save auth.json

# Later sessions: load saved state
agent-browser state load auth.json

Technical Analysis

The Skill directs users to save authenticated browser state to a predictable file named auth.json. Browser state can contain cookies and web-storage values associated with an authenticated session. Such values may function as bearer credentials: possession can be sufficient to access the corresponding account without knowing its password.

The documentation does not instruct users to apply restrictive file permissions, store the file outside the project directory, exclude it from source control and build artifacts, encrypt it, limit its lifetime, or securely delete it. It also demonstrates loading the saved state in later sessions, extending the period during which authentication material remains recoverable.

The reviewed files do not establish that the upstream CLI encrypts saved state. Consequently, this finding concerns the Skill's omission of mandatory controls when directing users to persist potentially sensitive authentication state, rather than an unsupported claim about the CLI's internal serialization format.

Attack Path

  1. A user logs in to a website through the automated browser.
  2. The authenticated session places cookies or tokens in browser storage.
  3. The user follows the example and saves the session to auth.json.
  4. The file remains in the working directory without documented access restrictions or source-control exclusions.
  5. Another local user, process, backup system, CI arti ...[truncated 972 chars]
Remediation
View remediation

Remediation Suggestions

  1. Warn explicitly that saved browser state may contain session credentials and must be handled as a secret.
  2. Store state outside the repository in a dedicated, access-controlled secrets directory.
  3. Create state files with owner-only permissions, such as mode 0600 on supported systems, and ensure the containing directory is similarly restricted.
  4. Add auth.json and broader browser-state filename patterns to .gitignore, packaging exclusions, backup exclusions, and CI artifact exclusions.
  5. Use short-lived, least-privileged test accounts instead of personal or production accounts.
  6. Prefer ephemeral browser sessions and avoid saving state unless persistence is necessary.
  7. Encrypt persisted state using an operating-system credential store or managed secret-storage service where supported.
  8. Define an expiration and secure-deletion procedure for state files after the automation task finishes.
  9. Revoke affected sessions immediately if a state file is exposed.
  10. Avoid predictable shared filenames when concurrent or multi-user execution is possible, and ensure temporary files are created securely without permissive default permissions.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · CONTRIBUTING.md (reported line 60)May include surrounding context.

md
## Adding New Commands to the Skill

Update SKILL.md when the upstream CLI adds new commands.
- Keep the Installation section
- Add new commands in the correct category
- Include usage examples

Context Window Stuffing

Medium
Category
Memory Poisoning
Confidence
85% confidence
Finding

Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.

Content

Scanner excerpt · SKILL.md (reported line 41)May include surrounding context.

agent-browser open # Navigate to page agent-browser snapshot -i # Get interactive elements with refs agent-browser click @e1 # Click element by ref agent-browser fill @e2 "text" # Fill input by ref agent-browser close # Close browser

text

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly enables uploading files, taking screenshots, exporting PDFs, and saving/loading browser state, but it does not warn that these actions can capture or transfer sensitive local and session data. In an agent context, this increases the risk of unintentional exfiltration of credentials, personal data, internal documents, or authenticated session material.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The recording and tracing features create artifacts that may contain full page contents, user interactions, cookies-preserved sessions, and debugging data, yet the skill provides no warning about the sensitivity of those captures. Because recording preserves cookies/storage from the current session, an agent could generate reusable artifacts containing authenticated or confidential information.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
92% confidence
Finding

The documented ability to save and later load browser session state enables persistence of cookies, tokens, and authenticated context across runs. Without warnings or handling guidance, this can lead to credential leakage, session hijacking, or reuse of privileged state by unintended parties or later tasks.

Content

Scanner excerpt · SKILL.md (reported line 236)May include surrounding context.

bash
agent-browser state save auth.json    # Save session state
agent-browser state load auth.json    # Load saved state

Example: Form submission

Session Persistence

Medium
Category
Rogue Agent
Confidence
94% confidence
Finding

The authentication example normalizes saving login state to a local file and reusing it in later sessions without any caution about secret handling. In an agent workflow, this makes accidental long-term persistence of authenticated access more likely and can enable unauthorized reuse if the file is exposed.

Content

Scanner excerpt · SKILL.md (reported line 265)May include surrounding context.

agent-browser wait --url "/dashboard" agent-browser state save auth.json

Later sessions: load saved state

agent-browser state load auth.json agent-browser open https://app.example.com/dashboard

text

Static analysis

No suspicious patterns detected.