Back to skill

Security audit

Browser Ops Publish

Security checks for vulnerabilities and agentic risk

Overview

This skill is a useful browser-routing helper, but it can automatically reuse your logged-in browser sessions and includes unsafe helper scripts that could expose cookies or run unintended commands.

Install only if you are comfortable with an agent using your active browser login state. Use a dedicated low-privilege browser profile, avoid internal or sensitive sites until the authenticated fallback asks for explicit per-domain approval, pin and review dependencies, and do not run the bundled helper scripts with untrusted URLs, queries, or limit values until their injection and cookie-file handling issues are fixed.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (6)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/web-trending.sh:10
Finding

Shell Command Injection Through the Trending Limit Argument

Content
View full analysis
&1) || true ``` ### Technical Analysis The second command-line argument is assigned directly to `LIMIT` without validating that it is numeric. It is then concatenated into a shell command string and executed with `eval`. Quoting `"$CMD"` does not make this safe because `eval` reparses the resulting string as shell syntax. Shell separators, command substitutions, redirections, or other metacharacters placed in `LIMIT` therefore become executable syntax. ### Attack Path 1. An attacker, untrusted prompt, or calling process controls the limit argument passed to `web-trending.sh`. 2. The attacker supplies a value containing a valid limit followed by shell syntax, such as a command s ...[truncated 576 chars]
Remediation
View remediation
100 )); then echo "Limit must be an integer from 1 to 100" >&2 exit 2 fi case "$PLATFORM" in twitter) CMD=(opencli twitter trending --limit "$LIMIT" -f md) ;; zhihu) CMD=(opencli zhihu hot --limit "$LIMIT" -f md) ;; hackernews) CMD=(opencli hackernews top --limit "$LIMIT" -f md) ;; # Define the remaining permitted commands in the same manner. esac result=$("${CMD[@]}" 2>&1) || true ``` Add regression tests using shell metacharacters, command substitutions, whitespace, negative numbers, and excessively large values. ]]>

T09 · Insecure Skill Coding Practices

Error
Location
scripts/web-search.sh:7
Finding

Python Code Injection Through the Search Query

Content
View full analysis
/dev/null || true ``` ### Technical Analysis `QUERY` is interpolated directly into Python source contained in a `python3 -c` argument. Although shell metacharacters produced by parameter expansion are not independently reparsed by the shell, quotes and Python syntax inside the query become part of the generated Python program. A crafted query can terminate the single-quoted Python string, execute additional Python statements, and comment out the remainder of the intended expression. Python can then invoke operating-system commands or directly read and transmit local data. ### Attack Path 1. The attacker controls the search query supplied to `web-search.sh`. 2. The attacker includes characters that close the Python string literal and add a Python expression or statement. 3. If Tavily and OpenCLI do not return an accepted result, execution reaches the Agent Browser fallback. 4. The script constructs a new Python program containing the attacker-controlled query. 5. `python3 -c` executes the injected Python code with the Agent’s privileges. The exploit path depends on reaching the fallback, but an attacker may deliberately use a query that causes the earlier search layers to fail or may target an environment where those layers are unavailable. ### Impact Assessment Exploitation enables arbitrary local code execution. The resulting Python process inherits the Agent’s user identity and environment, potentially exposing API keys, browser profiles, internal files, and the plaintext cookie store. ]]>
Remediation
View remediation
/dev/null || true ``` Also validate `LIMIT` as a bounded positive integer before passing it to external tools. Add tests containing single quotes, double quotes, newlines, backslashes, Python comment characters, and Unicode input. ]]>

T09 · Insecure Skill Coding Practices

Error
Location
scripts/sync-cookies.sh:142
Finding

Python Code Injection Through Cookie Injection and Login URLs

Content
View full analysis
${NC}" exit 1 fi python3 << PYEOF import json, os, asyncio async def main(): from playwright.async_api import async_playwright state_file = os.path.expanduser("$UNIFIED_STATE") data = json.load(open(state_file)) cookies = data.get("cookies", []) from urllib.parse import urlparse target = urlparse("$URL") domain = target.hostname or "" matching = [c for c in cookies if domain.endswith(c.get("domain","").lstrip("."))] async with async_playwright() as p: browser = await p.chromium.launch(headless=True) context = await browser.new_context() if pw_cookies: await context.add_cookies(pw_cookies) page = await context.new_page() response = await page.goto("$URL", wait_until="domcontentloaded", timeout=15000) asyncio.run(main()) PYEOF ``` The `login` fallback contains the same pattern: ```bash URL="${2:-https://example.com}" python3 << PYEOF import asyncio, json, os async def main(): from playwright.async_api import async_playwright async with async_playwright() as p: browser = await p.chromium.launch(headless=False) context = await browser.new_context() page = await context.new_page() await page.goto("$URL") input("登录完成后按 Enter...") cookies = await context.cookies() state = {"cookies": cookies, "origins": []} store = os.path.expanduser("$UNIFIED_STATE") json.dump(state, open(store, "w"), indent=2) await browser.close() asyncio.run(main()) PYEOF ``` ### Technical Analysis Because the ...[truncated 1255 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/sync-cookies.sh:16
Finding

Plaintext Session Cookies Written With Inconsistent Permissions and Unsafe Temporary Paths

Content
View full analysis
/dev/null || true sleep 1 agent-browser state save "$UNIFIED_STATE" 2>/dev/null agent-browser close 2>/dev/null ``` The `import-bu` path writes all converted cookie values to a fixed temporary filename: ```bash TMP_COOKIES="/tmp/browser-ops-bu-cookies.json" python3 -c " import json, os data = json.load(open(os.path.expanduser('$UNIFIED_STATE'))) cookies = [{k: v for k, v in c.items() if k not in ('size', 'session')} for c in data['cookies']] json.dump(cookies, open('$TMP_COOKIES', 'w'), indent=2) print(f'Converted {len(cookies)} cookies to browser-use format: $TMP_COOKIES') " ``` ### Technical Analysis The Skill consolidates browser session cookies from multiple domains into an unencrypted JSON file. The `login` branch later applies `chmod 600`, but the independent `export` branch does not. The effective permissions therefore depend on the user’s umask and on how `agent-browser state save` creates the file. The conversion branch uses the predictable path `/tmp/browser-ops-bu-cookies.json`, does not securely create it, does not enforce restrictive permissions, and does not remove it after use. This creates two risks: 1. Other local users or processes may read active session cookies. 2. A local attacker may pre-create the path as a symbolic link, causing the script to overwrite another file writable by the victim. ### Attack Path **Credential disclosure path:** 1. The ...[truncated 1030 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:65
Finding

Authenticated Browser Access Is Automatically Reused Without Per-Origin Authorization

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
references/setup.md:4
Finding

Unpinned Executable Dependencies and Browser Extension Components

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (60)

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill is presented as routing guidance, but the content explicitly instructs authenticated access using Chrome cookies and internal/SSO sites. That mismatch matters because users may treat it as passive documentation while it normalizes sensitive session reuse and cookie-backed retrieval, increasing risk of unauthorized data exposure.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill is presented as routing guidance, but the content explicitly instructs authenticated access using Chrome cookies and internal/SSO sites. That mismatch matters because users may treat it as passive documentation while it normalizes sensitive session reuse and cookie-backed retrieval, increasing risk of unauthorized data exposure.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

The skill is presented as routing guidance, but the content explicitly instructs authenticated access using Chrome cookies and internal/SSO sites. That mismatch matters because users may treat it as passive documentation while it normalizes sensitive session reuse and cookie-backed retrieval, increasing risk of unauthorized data exposure.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill is presented as routing guidance, but the content explicitly instructs authenticated access using Chrome cookies and internal/SSO sites. That mismatch matters because users may treat it as passive documentation while it normalizes sensitive session reuse and cookie-backed retrieval, increasing risk of unauthorized data exposure.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The skill is presented as routing guidance, but the content explicitly instructs authenticated access using Chrome cookies and internal/SSO sites. That mismatch matters because users may treat it as passive documentation while it normalizes sensitive session reuse and cookie-backed retrieval, increasing risk of unauthorized data exposure.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The skill is presented as routing guidance, but the content explicitly instructs authenticated access using Chrome cookies and internal/SSO sites. That mismatch matters because users may treat it as passive documentation while it normalizes sensitive session reuse and cookie-backed retrieval, increasing risk of unauthorized data exposure.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill is presented as routing guidance, but the content explicitly instructs authenticated access using Chrome cookies and internal/SSO sites. That mismatch matters because users may treat it as passive documentation while it normalizes sensitive session reuse and cookie-backed retrieval, increasing risk of unauthorized data exposure.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The skill is presented as routing guidance, but the content explicitly instructs authenticated access using Chrome cookies and internal/SSO sites. That mismatch matters because users may treat it as passive documentation while it normalizes sensitive session reuse and cookie-backed retrieval, increasing risk of unauthorized data exposure.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill is presented as routing guidance, but the content explicitly instructs authenticated access using Chrome cookies and internal/SSO sites. That mismatch matters because users may treat it as passive documentation while it normalizes sensitive session reuse and cookie-backed retrieval, increasing risk of unauthorized data exposure.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill is presented as routing guidance, but the content explicitly instructs authenticated access using Chrome cookies and internal/SSO sites. That mismatch matters because users may treat it as passive documentation while it normalizes sensitive session reuse and cookie-backed retrieval, increasing risk of unauthorized data exposure.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger patterns are very broad and overlap with ordinary user language such as '帮我看', '打开.*链接', '网站', and 'download.*page'. In an automatic skill-selection system, this can cause the skill to activate unexpectedly on benign requests and then steer the agent into shell, browser, or cookie-backed actions the user did not specifically intend.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill explicitly authorizes use of browser cookies and access to internal or SSO-protected sites without a prominent privacy warning. In context, this is more dangerous because the skill targets authenticated browsing, so automatic session reuse may expose private company data, personal accounts, or privileged internal resources without clear informed consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The instruction to auto-upgrade from WebFetch to cookie-backed opencli web read without asking the user removes consent for a privacy-sensitive escalation. This can silently switch from public-page retrieval to authenticated access using local browser session state, materially increasing the sensitivity of the accessed data and the user's exposure.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

This scenario explicitly expects reuse of login state for an internal company dashboard and taking screenshots, but does not require any user-facing warning or confirmation about sensitive corporate data, session scope, or screenshot contents. In context, this is especially dangerous because internal dashboards commonly contain confidential business information, personal data, or administrative controls, and authenticated browser reuse can expose far more than the user intended.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README explicitly promotes reusing Chrome cookies/login state to read internal pages, which can cause an agent to access authenticated or internal resources without clear user confirmation, scope limits, or privacy warnings. In an agent skill whose purpose is browser routing, this context makes the issue more dangerous because the capability is normalized and presented as a default convenience path rather than a high-risk action.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README includes autonomous browser-operation and account-registration examples without warning that these commands can perform irreversible, state-changing actions such as creating accounts, submitting forms, or modifying data. Because this skill is specifically designed to guide agent tool selection, omission of guardrails increases the chance that an agent will execute impactful actions on third-party sites without explicit user confirmation.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill documents shell, network, filesystem, and environment-dependent operations but declares no tool restrictions. In an agent setting, missing scope boundaries increases the chance the skill is invoked with broader capabilities than necessary, enabling unintended command execution or data access if the content is modified or misused.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest says the skill is not for cross-host remote browser control, yet later documents remote/cloud execution features like browser-use remote. This contradiction can bypass operator expectations and cause data, credentials, or browsing actions to be sent to remote infrastructure despite the declared limitation.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
83% confidence
Finding

The skill includes instructions to send search queries and URLs to third-party services such as Brave and Firecrawl. External transmission is especially sensitive here because the skill also handles internal sites, cookies, and potentially authenticated content; without strict routing controls, users may inadvertently send sensitive URLs or derived data to external providers.

Content

Scanner excerpt · SKILL.md (reported line 155)May include surrounding context.

md
tavily extract "https://url"                        # URL 内容提取

# Brave — 独立索引,不依赖 Google/Bing
curl -s "https://api.search.brave.com/res/v1/web/search?q=query" \
  -H "X-Subscription-Token: $BRAVE_API_KEY"

# Firecrawl — JS 渲染 + Markdown 提取 (免费 500 次)

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Later instructions actively direct use of remote execution features even though the skill claims remote control is out of scope. That inconsistency is dangerous in an agent environment because users and platform policy may rely on the manifest's narrower trust boundary when deciding whether the skill may access sensitive sites or sessions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script embeds all user-facing test queries in Chinese, which imposes a specific language context without any documented opt-in or indication that the skill is intentionally region-specific. Under the policy rules, forcing a locale or language without user choice is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The eval set uses very broad, generic prompts such as '帮我打开/访问/下载' and similar browsing verbs, which can cause the skill to activate for loosely related user requests without tight scoping. In a skill that can fetch pages, reuse login state, and escalate to browser automation, overbroad triggering increases the chance of unintended web access, unnecessary data exposure, or use of higher-risk tooling when a simpler response would suffice.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.