Back to skill

Security audit

Agent Browser 0.2.0

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent browser-automation wrapper, but it gives agents access to authenticated browser state and saved session files without enough safety guidance.

Install only if you trust the agent-browser package source and are comfortable with an agent controlling browser sessions. Pin a reviewed package version or commit where possible. Treat saved state files, traces, screenshots, videos, cookies, localStorage, and credentials as sensitive; keep them out of repositories and shared folders, restrict file permissions, and delete or revoke sessions when finished.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:19
Finding

Unpinned Third-Party Installation Creates a Supply-Chain Execution Risk

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:19-32; CONTRIBUTING.md:23-26
Vulnerability Type: Unpinned and mutable third-party dependencies
Risk Level: Medium

Vulnerable Code

SKILL.md:19-32:

bash
npm install -g agent-browser
agent-browser install
agent-browser install --with-deps
bash
git clone https://github.com/vercel-labs/agent-browser
cd agent-browser
pnpm install
pnpm build
agent-browser install

CONTRIBUTING.md:23-26:

bash
npm install -g agent-browser@latest

Technical Analysis

The installation instructions execute mutable third-party content without pinning an audited package version, commit hash, lockfile state, or integrity digest. The @latest specifier explicitly selects whichever release is current when installation occurs. Similarly, cloning the repository without checking out a fixed commit executes the current default branch through pnpm install, lifecycle scripts, and the build process.

Package-manager lifecycle hooks and transitive dependencies can execute arbitrary code during installation. The subsequent agent-browser install --with-deps operation may also install browser and operating-system dependencies. While the documented npm package and GitHub repository appear consistent with the stated upstream project, the instructions provide no protection against a future compromised release, maintainer account, repository branch, or transitive dependency.

Attack Path

  1. An attacker compromises the upstream package, maintainer credentials, repository branch, or a transitive dependency.
  2. The attacker publishes a malicious release under the existing package name or inserts malicious installation/build logic into the mutable repository state.
  3. A user follows the documented npm install -g agent-browser, @latest, or unpinned source-build instructions.
  4. npm or pnpm downloads the attacker-controlled content.
  5. Instal ...[truncated 918 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin agent-browser to a specific reviewed version rather than using an implicit current release or @latest.
  2. For source installation, check out a specific reviewed commit hash or signed release tag before installing dependencies or building.
  3. Supply and enforce a lockfile for transitive dependencies.
  4. Document package-signature, provenance, checksum, or integrity verification where supported.
  5. Avoid global installation where possible; prefer a project-local, isolated environment.
  6. Explain whether --with-deps requires elevated privileges and recommend running unprivileged steps separately from narrowly scoped privileged operations.
  7. Review dependency changes before updating the pinned package version or source commit.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:253
Finding

Authentication State Is Persisted Without Sensitive-File Protection Guidance

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:235-236; SKILL.md:253-266
Vulnerability Type: Plaintext persistence of sensitive browser session state
Risk Level: Medium

Vulnerable Code

SKILL.md:235-236:

bash
agent-browser state save auth.json    # Save session state
agent-browser state load auth.json    # Load saved state

SKILL.md:253-266:

bash
# Login once
agent-browser open https://app.example.com/login
agent-browser snapshot -i
agent-browser fill @e1 "username"
agent-browser fill @e2 "password"
agent-browser click @e3
agent-browser wait --url "/dashboard"
agent-browser state save auth.json

# Later sessions: load saved state
agent-browser state load auth.json
agent-browser open https://app.example.com/dashboard

Technical Analysis

The authentication example saves browser state to the predictable relative path auth.json immediately after login. Browser state files commonly contain cookies and local-storage values, including reusable authentication tokens. The documentation does not identify the file as sensitive or require restrictive permissions, encryption, placement outside a repository, source-control exclusion, expiration, revocation, or secure deletion.

A relative filename is normally created in the current working directory. When the command is executed inside a project, the resulting state file may be included accidentally in version control, archives, CI artifacts, shared workspaces, or backups. Any party able to read and import a still-valid state file may be able to assume the associated browser session without obtaining the original password.

Attack Path

  1. A user signs in to a website through the browser automation workflow.
  2. The command saves authenticated cookies and storage state to auth.json.
  3. The file remains in a project directory, shared workspace, backup, artifact, or location with overly broad read permissions.

...[truncated 962 chars]

Remediation
View remediation

Remediation Suggestions

  1. Explicitly state that saved browser-state files must be treated as authentication secrets.
  2. Save state outside repositories and shared working directories.
  3. Create state files with owner-only permissions, such as mode 0600 on Unix-like systems.
  4. Add state-file patterns such as auth.json and dedicated state directories to .gitignore.
  5. Prefer encrypted secret storage or ephemeral session handling where supported.
  6. Use unique, non-predictable paths when workflows could share a filesystem.
  7. Prevent state files from being uploaded as CI artifacts, included in logs, or copied into container images.
  8. Delete state files securely when no longer required and revoke the corresponding server-side sessions after use.
  9. Use short-lived, least-privileged test accounts for automation rather than privileged production accounts.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · CONTRIBUTING.md (reported line 60)May include surrounding context.

md
## Adding New Commands to the Skill

Update SKILL.md when the upstream CLI adds new commands.
- Keep the Installation section
- Add new commands in the correct category
- Include usage examples

Context Window Stuffing

Medium
Category
Memory Poisoning
Confidence
85% confidence
Finding

Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.

Content

Scanner excerpt · SKILL.md (reported line 41)May include surrounding context.

agent-browser open # Navigate to page agent-browser snapshot -i # Get interactive elements with refs agent-browser click @e1 # Click element by ref agent-browser fill @e2 "text" # Fill input by ref agent-browser close # Close browser

text

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly documents use of HTTP basic auth credentials and saving/loading authenticated browser state, but does not warn that credentials, cookies, and tokens may be stored, reused, or exposed via files, logs, screenshots, traces, or shared workspaces. In an agent context, this can lead to unintended persistence and leakage of secrets or authenticated sessions across tasks or users.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
95% confidence
Finding

Saving and later loading browser session state enables persistence of cookies, tokens, and other authenticated context across runs. Without safeguards or warnings, this can cause session hijacking, cross-task contamination, or accidental reuse of privileged state by other agents or users with filesystem access.

Content

Scanner excerpt · SKILL.md (reported line 236)May include surrounding context.

bash
agent-browser state save auth.json    # Save session state
agent-browser state load auth.json    # Load saved state

Example: Form submission

Session Persistence

Medium
Category
Rogue Agent
Confidence
96% confidence
Finding

The authentication example normalizes saving and reloading an auth.json session file without highlighting that it may contain reusable authenticated state. In the skill context, this is more dangerous because the tool is designed for automation, making silent replay of privileged sessions straightforward and scalable.

Content

Scanner excerpt · SKILL.md (reported line 265)May include surrounding context.

agent-browser wait --url "/dashboard" agent-browser state save auth.json

Later sessions: load saved state

agent-browser state load auth.json agent-browser open https://app.example.com/dashboard

text

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill describes commands that write screenshots, PDFs, videos, traces, and state to local files without warning that files will be created or overwritten and may contain sensitive page contents. In agent-driven environments, artifacts can silently accumulate, overwrite existing files, or expose confidential data captured from browser sessions.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.