T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/configure-browser.js:28- Finding
Private-Network SSRF Protection Is Explicitly Disabled
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a disclosed local Chrome automation helper, but it weakens browser network protections and includes unsafe local scripts that can overwrite configuration or run shell commands from unvalidated inputs.
Install only in a trusted local environment after reviewing the scripts. Avoid the one-click setup unless you are comfortable with it rewriting OpenClaw browser configuration and enabling private-network access; prefer a hostname allowlist and back up openclaw.json first. Do not pass untrusted port, version, or output-file arguments to the scripts, and be aware that stop-chrome.js may close unrelated Chrome sessions.
scripts/configure-browser.js:28Private-Network SSRF Protection Is Explicitly Disabled
scripts/start-chrome.js:14Command Injection Through the Chrome Debugging Port Argument
scripts/package.js:15Command Injection and Unrestricted Output Paths in Packaging Scripts
scripts/stop-chrome.js:63Shutdown Script Forcibly Terminates All Chrome Processes
scripts/configure-browser.js:17Existing OpenClaw Browser Configuration Is Destructively Replaced
The README explicitly advertises '绕过 SSRF 限制' (bypass SSRF restrictions) as a use case, which is a direct abuse-oriented capability rather than a normal browser automation function. In the context of a skill that also enables private-network browser access, this materially increases the likelihood of internal network access, cloud metadata probing, or access to otherwise protected services through the browser channel.
Referenced artifact was not completely inspected
node scripts/stop-chrome.js
Referenced artifact was not completely inspected
node scripts/stop-chrome.js
This markdown file presents all operational instructions in Chinese and does not indicate that users may choose another language. That can violate a language/locale policy when a skill effectively forces one language without explicit user opt-in or documented justification.
The installation guide instructs users to run node scripts/setup.js to automatically configure OpenClaw, but it does not explain what files will be modified, whether changes are reversible, or ask users to review the script first. In a skill installation context, encouraging execution of an opaque setup script can lead to unintended configuration changes or persistence of unsafe settings.
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
Linux:
# 安装 Chrome
sudo apt install google-chrome-stable
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
Linux:
# 安装 Chrome
sudo apt install google-chrome-stable
The guide recommends forcibly killing processes with taskkill /F and kill -9 without warning that these commands bypass graceful shutdown and may terminate the wrong process if the PID is misidentified. This can cause data loss, browser profile corruption, or disruption of unrelated applications on the host.
The troubleshooting section recommends destructive force-kill commands (taskkill /F /IM chrome.exe and taskkill /F /PID <PID>) without an explicit warning that they may terminate unrelated browser sessions or the wrong process, causing data loss or system disruption. In this skill’s context, users are already instructed to manage a local Chrome debugging instance, so the commands are operationally relevant, but the lack of safety guidance makes negligent misuse plausible.
The README describes setup.js as a one-click action that performs startup, configuration, and validation, but does not clearly warn that it changes local configuration. Hidden or under-documented configuration mutation is risky for a security-sensitive browser skill because it may silently enable unsafe defaults or alter agent/network behavior without informed user consent.
The security section normalizes dangerouslyAllowPrivateNetwork: true as a configurable detail even though the README elsewhere presents SSRF bypass as a capability. This combination lowers operator suspicion and can lead users to deploy a browser profile that can reach internal services, making misuse or accidental exposure substantially more dangerous in real environments.
The documentation instructs users to free port 9222 by forcefully terminating processes (taskkill /F and kill -9) without any warning to verify process identity first. This can cause accidental termination of unrelated applications or system processes if the user targets the wrong PID, leading to disruption or data loss. In a skill specifically centered on browser debugging, port 9222 is likely to be used by Chrome, which makes the guidance understandable, but the omission of safety checks still makes it operationally unsafe.
The skill explicitly promotes enabling an SSRF policy with dangerouslyAllowPrivateNetwork: true and describes it as allowing access to arbitrary websites, which weakens network boundary protections for browser automation. In the context of an agent skill, this can expose internal services, cloud metadata endpoints, localhost-only admin panels, or other private network resources to unintended access, and the text does not provide an adequate security warning or constrained allowlist guidance as the default.
The description text is written only in Chinese, which indicates a language-specific skill presentation without offering any language choice or documenting that the skill is intended for a Chinese-only context. The policy requires avoiding forced language/locale constraints unless the user can opt in or the limitation is clearly justified.
The script silently rewrites the OpenClaw browser configuration to set ssrfPolicy.dangerouslyAllowPrivateNetwork to true, which weakens protections against requests to internal/private network resources. In an agent/browser-automation context, this can enable access to localhost or internal services through browser-driven workflows, materially increasing SSRF-style abuse risk beyond what the script’s description suggests.
The file's docstring and all console messages are written only in Chinese, which imposes a specific language on users without any opt-in or alternative locale handling. This is a natural-language policy concern because the skill does not offer language selection or document a justified region-specific constraint.
The script accepts the output filename from process.argv[2] and later interpolates it into shell command strings in the system-zip fallback. An attacker supplying a crafted filename containing shell metacharacters or path manipulation can execute arbitrary commands or write archives to unintended locations, especially on macOS/Linux where the string is passed to a shell via exec(). The skill context makes this more dangerous because packaging utilities are often run locally by developers with significant filesystem access.
The fallback packaging path builds a shell command string and executes it with child_process.exec(). Because command construction incorporates runtime-controlled values and passes them through a shell, it creates command-injection risk if an attacker can influence the output filename or execution environment. In a packaging script, this is unnecessary exposure because ZIP creation can be done without invoking a shell.
The file's natural-language strings, including the header comment and all console output, are written in Chinese only. This imposes a specific language on users without any opt-in, fallback, or documented region-specific justification, which matches the language/locale policy violation criteria.
The script takes a user-controlled version argument and interpolates it directly into shell commands executed via child_process.exec for both PowerShell and zip invocation. Because exec invokes a shell, a crafted version string containing shell metacharacters can break out of the intended filename context and execute arbitrary commands on the host running the packaging script.
The script launches Chrome with the DevTools remote debugging interface enabled, but it does not warn users that this can expose browser state, cookies, local files, and powerful browser control capabilities to any process or host that can reach the debugging port. Although it prints a localhost URL, the code does not validate the port input, restrict exposure beyond Chrome defaults, or explain the security implications of running a debug-enabled browser profile.
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
console.error(' 或使用:which "Google Chrome"');
} else {
console.error(' 确认 Chrome 已安装:which google-chrome');
console.error(' 或使用:sudo apt install google-chrome-stable');
}
process.exit(1);
}
The script's natural-language interface, comments, usage text, status messages, and recommendations are all presented in Chinese, with no indication that users can select another language or locale. This is a language/locale policy concern because the skill imposes a specific language on all users without opt-in or documented justification.
The file content, headings, instructions, and warnings are all presented only in Chinese. Under the language/locale policy, forcing a specific language without user opt-in or documented justification can be a natural-language policy violation.
The skill documentation is written entirely in Chinese (本地 Chrome 调试模式浏览器自动化配置技能) and provides no indication that another language is available or that the skill is intended only for a Chinese-speaking audience. The policy requires avoiding forced language/locale constraints unless the user is given a choice or the restriction is clearly justified.
Detected: suspicious.dangerous_exec