Back to skill

Security audit

BrowserAgent

Security checks for vulnerabilities and agentic risk

Overview

This browser automation skill is mostly disclosed, but it teaches bot-detection evasion and unsafe browser/session practices that deserve manual review before installation.

Install only if you need this exact browser-automation guidance and are comfortable reviewing each command. Prefer project-local, pinned Playwright dependencies; avoid stealth and bot-detection bypass guidance except in explicitly authorized testing; do not disable the Chromium sandbox; and treat storageState files, screenshots, recordings, and downloads as sensitive data.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:42
Finding

Unpinned Global Third-Party Package Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 42–48
Vulnerability Type: Unpinned and globally installed dependencies
Risk Level: Medium

bash
# Install Playwright
npm install -g playwright

# Install browsers (Chrome, Firefox, Safari)
npx playwright install

# Install Chrome extension for stealth (optional)
npm install -g playwright-extra playwright-extra-plugin-stealth

Technical Analysis

The installation instructions retrieve the latest available versions of multiple npm packages without a version constraint or lockfile. The packages are installed globally, expanding their influence beyond an isolated project environment. The npx playwright install command also downloads browser binaries based on the installed Playwright package.

Package installation can execute npm lifecycle scripts. Consequently, a compromised package release, transitive dependency, npm registry response, or future malicious version could execute code with the privileges of the user following these instructions. The optional stealth packages increase the supply-chain surface and are not required for the core browser-automation functionality.

Attack Path

  1. An attacker compromises a listed npm package, one of its transitive dependencies, or the package distribution channel.
  2. A user follows the Skill instructions and runs an unpinned global installation command.
  3. npm resolves the compromised release because no reviewed version or lockfile is enforced.
  4. Malicious package code or an installation lifecycle script executes under the installing user's account.
  5. The payload may access user-readable files, environment variables, browser data, and credentials, or modify globally installed tooling.

Impact Assessment

Successful exploitation could provide arbitrary code execution with the privileges of the user performing the installation. The accessible scope may include user files, environment secrets ...[truncated 221 chars]

Remediation
View remediation

Remediation Suggestions

  • Replace global installations with project-local dependencies.
  • Pin every dependency to a reviewed exact version.
  • Commit a lockfile and use npm ci to enforce reproducible dependency resolution.
  • Review package provenance, maintainers, integrity metadata, and lifecycle scripts before installation.
  • Use a trusted npm registry and retain registry integrity verification.
  • Remove playwright-extra and playwright-extra-plugin-stealth from the standard procedure unless a documented use case explicitly requires them.
  • Execute dependency installation in a non-privileged, isolated environment without access to production credentials.

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:119
Finding

Authenticated Browser State Stored in an Unprotected Local File

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 119–134
Vulnerability Type: Insecure storage of reusable authentication material
Risk Level: High

javascript
await page.goto('https://example.com/login');
await humanType('#email', 'user@example.com');
await humanType('#password', 'secret123');
await humanClick('button[type="submit"]');

// Wait for login to complete
await page.waitForNavigation({ waitUntil: 'networkidle' });

// Save cookies/storage for reuse
await page.context().storageState({ path: './session.json' });
await browser.close();

// Reuse session later
const browser2 = await chromium.launch({ headless: false });
const context = await browser2.newContext({
  storageState: './session.json'
});

Technical Analysis

Playwright storage-state files can contain session cookies and local-storage values, including bearer tokens or other reusable authentication artifacts. The example writes this sensitive state to a predictable relative path named session.json without specifying restrictive file permissions, encryption, retention limits, cleanup, or exclusion from version control.

The literal username and password values are examples rather than evidence of real embedded credentials. The primary vulnerability is the handling of the resulting authenticated session state. Possession of that file may allow an attacker to bypass the original login flow, including password checks and potentially multi-factor authentication, until the captured session expires or is revoked.

Sending credentials to the login site is necessary for the declared login-automation function when the destination is selected and trusted by the user. Persisting the resulting session in an unprotected project-local file is not the minimum privilege required.

Attack Path

  1. A user adapts the example to authenticate to a real service.
  2. Playwright writes cookies and local-storage tokens to `./session ...[truncated 897 chars]
Remediation
View remediation

Remediation Suggestions

  • Store browser state outside the project and source tree.
  • Create the storage file with owner-only permissions, such as mode 0600 on supported systems.
  • Add all browser storage-state files to .gitignore and artifact-exclusion rules.
  • Delete the state immediately after the workflow unless persistence is explicitly required.
  • Encrypt persistent state at rest using an operating-system credential store or managed secret store.
  • Use short-lived, least-privileged sessions and revoke them after automation completes.
  • Obtain credentials through interactive input, environment variables, or a secret manager rather than source literals.
  • Display a clear warning that Playwright storage state must be handled as a credential.

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:285
Finding

Chromium Sandbox Disabled During Untrusted Web Navigation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 285–291
Vulnerability Type: Unsafe browser process configuration
Risk Level: High

javascript
const browser = await playwright.chromium.launch({
  headless: false,
  args: [
    '--disable-blink-features=AutomationControlled',
    '--no-sandbox',
    '--disable-dev-shm-usage'
  ]
});

Technical Analysis

The --no-sandbox argument disables an important Chromium security boundary intended to contain compromised renderer processes. It is not required for ordinary Playwright automation or for simulating human input. Because the declared functionality includes navigating arbitrary websites, extracting dynamic data, logging in, and downloading files, the browser must be treated as processing potentially hostile content.

Disabling the sandbox does not independently create a browser exploit. However, if a visited page successfully exploits a Chromium vulnerability, the absence of sandboxing significantly reduces containment and can make access to host-level resources easier. This option therefore exceeds the minimum privileges needed for the Skill's normal functionality.

Attack Path

  1. The automation launches Chromium with --no-sandbox.
  2. The user or automated workflow navigates to an attacker-controlled or compromised website.
  3. The page exploits a vulnerability in Chromium, a renderer component, or a supported browser feature.
  4. Because the sandbox is disabled, the compromised browser process has fewer isolation barriers.
  5. The exploit accesses resources available to the browser process, potentially including user files, environment data, downloaded content, and authentication state.

Impact Assessment

The obtainable privileges are bounded by the operating-system account running Chromium, but successful exploitation may provide access to that account's readable files, environment variables, session files, and network capa ...[truncated 215 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove the --no-sandbox browser argument from all standard examples.
  • Run Chromium as a non-privileged user with its normal sandbox enabled.
  • Keep Playwright and browser binaries updated to reviewed security-patched versions.
  • If an exceptional environment cannot support Chromium sandboxing, use a disposable, non-privileged container or virtual machine.
  • Do not expose host secrets, browser profiles, sensitive environment variables, or writable host mounts to an unsandboxed browser.
  • Apply outbound network restrictions and filesystem isolation appropriate to the destinations being automated.
  • Document that disabling the browser sandbox is an exceptional compatibility workaround, not a stealth or human-behavior feature.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (10)

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill markets itself for sites with bot detection and later includes direct evasion techniques, while also presenting ethical caveats that do not constrain the examples. That mismatch normalizes bypass behavior and increases the likelihood the skill is used to evade site defenses rather than for legitimate testing.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
81% confidence
Finding

The skill instructs users to invoke Playwright through npx without pinning a specific version, which can lead to execution of whatever package version is current at install time. This creates a supply-chain risk because upstream package compromise or breaking changes could result in unexpected code execution in the local environment.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill recommends persisting browser storage state to './session.json' without warning that this file may contain active session tokens, cookies, or other authentication artifacts. If the file is left on disk, committed to source control, or accessed by other local users/processes, accounts can be hijacked without needing passwords.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The documentation encourages screenshots, element captures, and video recording without any privacy or data-handling safeguards. These features can capture credentials, personal data, session details, or proprietary content, and the skill does not warn users to limit scope, secure outputs, or obtain consent.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly provides stealth and anti-detection techniques, including use of a stealth plugin, disabling automation indicators, and overriding browser fingerprint properties like navigator.webdriver, plugins, and languages. This goes beyond normal automation and materially enables bypass of bot-detection controls, which are often relied on as security and abuse-prevention measures.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The stealth example forces English-language settings as part of fingerprint spoofing, which is not user-driven and supports deception about client identity. While lower severity than direct credential theft, it contributes to anti-detection behavior and may misrepresent the user's environment to bypass locale-based checks or influence content served.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 561)May include surrounding context.

md
1. **Respect robots.txt** - Check site's scraping policy
2. **Rate limiting** - Add delays (2-5s between actions)
3. **Terms of Service** - Don't violate site ToS
4. **Personal data** - Don't scrape PII without consent
5. **Authentication** - Only use your own credentials
6. **Copyright** - Respect intellectual property
7. **Server load** - Don't overwhelm servers

Rp1

Medium
Category
MCP Rug Pull
Confidence
81% confidence
Finding

This command again references Playwright via npx without a pinned version, leaving users exposed to non-deterministic package resolution and possible malicious or compromised upstream releases. In a skill that encourages broad browser automation, that risk is amplified because the dependency will run with local user privileges.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
81% confidence
Finding

Using 'npx playwright' for code generation without version pinning carries the same supply-chain and reproducibility risk as other unpinned package invocations. Because codegen tools may access live websites, sessions, and local browser data, execution of a malicious version could expose sensitive information.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The page context example specifies locale 'en-US' and timezone 'America/New_York', which can steer agents toward a specific regional profile by default. Because the documentation does not frame these as optional placeholders or ask for user preference, this is a natural-language locale policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.