Back to skill

Security audit

Browser Use 3.0

Security checks across malware telemetry and agentic risk

Overview

This browser automation skill is coherent and disclosed, but it defaults to controlling the user's signed-in Chrome session with broad CDP authority.

Install only if you are comfortable letting the agent drive your real signed-in Chrome browser. Prefer the cloud or isolated browser mode for banking, email, admin panels, purchases, posting, or any sensitive workflow, and require explicit confirmation before account actions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Credential Access

High
Category
Privilege Escalation
Content
## Browser Modes

- **Local Chrome (default)**: attaches to the user's running Chrome/Chromium via CDP — preserves logins and cookies. No browser ids or profile selection needed.
- **Cloud browser**: fresh, isolated, managed Chrome hosted by Browser Use — see Cloud Browsers below.
- **Explicit endpoint**: set `BU_CDP_URL` (HTTP DevTools endpoint) or `BU_CDP_WS` to target any CDP browser.
Confidence
95% confidence
Finding
Chrome/Chromium via CDP — preserves logins and cookies

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.