Back to skill

Security audit

Browser Local Chrome

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed local Chrome automation helper, but it weakens browser network protections and includes unsafe local scripts that can overwrite configuration or run shell commands from unvalidated inputs.

Install only in a trusted local environment after reviewing the scripts. Avoid the one-click setup unless you are comfortable with it rewriting OpenClaw browser configuration and enabling private-network access; prefer a hostname allowlist and back up openclaw.json first. Do not pass untrusted port, version, or output-file arguments to the scripts, and be aware that stop-chrome.js may close unrelated Chrome sessions.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (5)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/configure-browser.js:28
Finding

Private-Network SSRF Protection Is Explicitly Disabled

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/start-chrome.js:14
Finding

Command Injection Through the Chrome Debugging Port Argument

Content
View full analysis
{ ``` ### Technical Analysis `CDP_PORT` is read directly from `process.argv[2]` and inserted into a command string passed to `child_process.exec()`. No numeric validation, range validation, escaping, or allowlisting is applied. `exec()` invokes a command shell. Consequently, shell metacharacters contained in the supplied port argument are interpreted as shell syntax rather than as part of a Chrome argument. On a POSIX platform, an argument conceptually equivalent to `9222; ` can terminate the Chrome command and append another command. Platform-specific command separators can produce the same outcome on Windows. The normal `setup.js` path uses the hardcoded value `9222`, but `start-chrome.js` is documented and exposed as a directly invokable script accepting a caller-provided port. ### Attack Path 1. An attacker gains the ability to influence how `start-chrome.js` is invoked, such as through ...[truncated 822 chars]
Remediation
View remediation
65535) { throw new Error('The CDP port must be between 1 and 65535.'); } const child = spawn(CHROME_PATH, [ `--remote-debugging-port=${port}`, `--user-data-dir=${USER_DATA_DIR}`, '--no-first-run', '--no-default-browser-check' ], { shell: false, detached: true }); ``` ]]>

T09 · Insecure Skill Coding Practices

Error
Location
scripts/package.js:15
Finding

Command Injection and Unrestricted Output Paths in Packaging Scripts

Content
View full analysis
{ ``` From `scripts/simple-package.js`: ```js const SKILL_DIR = path.join(__dirname, '..'); const VERSION = process.argv[2] || '1.1.0'; const ZIP_FILE = `browser-local-chrome-v${VERSION}.zip`; function packageWindows() { const command = ` $files = Get-ChildItem -Path "${SKILL_DIR}" -Recurse -File | Where-Object { $_.FullName -notmatch 'node_modules' -and $_.FullName -notmatch '\\.zip$' -and $_.FullName -notmatch '\\.git' } Compress-Archive -Path $files.FullName -DestinationPath "${path.join(SKILL_DIR, ZIP_FILE)}" -Force `; exec(`powershell -Command "${command}"`, (error, stdout, stderr) => { ``` ```js function packageUnix() { const cwd = path.dirname(SKILL_DIR); const skillName = path.basename(SKILL_DIR); const command = `cd "${cwd}" && zip -r "${ZIP_FILE}" "${skillName}" \ -x "*.zip" \ -x "*/node_modules/*" \ -x "*/.git/*"`; exec(command, (error, stdout, stderr) => { ``` ### Technical ...[truncated 1786 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/stop-chrome.js:63
Finding

Shutdown Script Forcibly Terminates All Chrome Processes

Content
View full analysis
{ if (error) { if (error.code === 128 || error.code === 1 || (stderr && stderr.includes('no process'))) { console.log('ℹ️ Chrome 进程未运行'); } else { console.error('❌ 关闭失败:', error.message); } } else { console.log('✅ Chrome 已关闭'); if (stdout) console.log(stdout); } ``` ### Technical Analysis The script initially attempts to close CDP pages, but it subsequently calls `forceKill()`. That function selects processes solely by executable name: - Windows: every process named `chrome.exe` - macOS: every process matching `Google Chrome` - Linux: every process matching `chrome`, using `SIGKILL` The script does not store the PID of the Chrome process it starts and does not verify the target process's command line or user-data directory. It therefore cannot distinguish the isolated debugging instance from ordinary Chrome sessions or unrelated automation. ### Attack Path 1. A user has one or more normal Chrome sessions running alongside the Skill-managed instance. 2. The user or an automated workflow runs `node scripts/stop-chrome.js`. 3. The script closes CDP pages or encounters a CDP error. 4. It invokes `taskkill` or `killall` using only the Chrome process name. 5. Every matching process accessible to the current user is forcibl ...[truncated 429 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/configure-browser.js:17
Finding

Existing OpenClaw Browser Configuration Is Destructively Replaced

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (33)

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The README explicitly advertises '绕过 SSRF 限制' (bypass SSRF restrictions) as a use case, which is a direct abuse-oriented capability rather than a normal browser automation function. In the context of a skill that also enables private-network browser access, this materially increases the likelihood of internal network access, cloud metadata probing, or access to otherwise protected services through the browser channel.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 51)May include surrounding context.

md
node scripts/stop-chrome.js

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 90)May include surrounding context.

md
node scripts/stop-chrome.js

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file presents all operational instructions in Chinese and does not indicate that users may choose another language. That can violate a language/locale policy when a skill effectively forces one language without explicit user opt-in or documented justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The installation guide instructs users to run node scripts/setup.js to automatically configure OpenClaw, but it does not explain what files will be modified, whether changes are reversible, or ask users to review the script first. In a skill installation context, encouraging execution of an opaque setup script can lead to unintended configuration changes or persistence of unsafe settings.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · INSTALL.md (reported line 217)May include surrounding context.

Linux:

bash
# 安装 Chrome
sudo apt install google-chrome-stable

端口被占用

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · RELEASE.md (reported line 240)May include surrounding context.

Linux:

bash
# 安装 Chrome
sudo apt install google-chrome-stable

端口被占用

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The guide recommends forcibly killing processes with taskkill /F and kill -9 without warning that these commands bypass graceful shutdown and may terminate the wrong process if the PID is misidentified. This can cause data loss, browser profile corruption, or disruption of unrelated applications on the host.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The troubleshooting section recommends destructive force-kill commands (taskkill /F /IM chrome.exe and taskkill /F /PID <PID>) without an explicit warning that they may terminate unrelated browser sessions or the wrong process, causing data loss or system disruption. In this skill’s context, users are already instructed to manage a local Chrome debugging instance, so the commands are operationally relevant, but the lack of safety guidance makes negligent misuse plausible.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The README describes setup.js as a one-click action that performs startup, configuration, and validation, but does not clearly warn that it changes local configuration. Hidden or under-documented configuration mutation is risky for a security-sensitive browser skill because it may silently enable unsafe defaults or alter agent/network behavior without informed user consent.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The security section normalizes dangerouslyAllowPrivateNetwork: true as a configurable detail even though the README elsewhere presents SSRF bypass as a capability. This combination lowers operator suspicion and can lead users to deploy a browser profile that can reach internal services, making misuse or accidental exposure substantially more dangerous in real environments.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation instructs users to free port 9222 by forcefully terminating processes (taskkill /F and kill -9) without any warning to verify process identity first. This can cause accidental termination of unrelated applications or system processes if the user targets the wrong PID, leading to disruption or data loss. In a skill specifically centered on browser debugging, port 9222 is likely to be used by Chrome, which makes the guidance understandable, but the omission of safety checks still makes it operationally unsafe.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill explicitly promotes enabling an SSRF policy with dangerouslyAllowPrivateNetwork: true and describes it as allowing access to arbitrary websites, which weakens network boundary protections for browser automation. In the context of an agent skill, this can expose internal services, cloud metadata endpoints, localhost-only admin panels, or other private network resources to unintended access, and the text does not provide an adequate security warning or constrained allowlist guidance as the default.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The description text is written only in Chinese, which indicates a language-specific skill presentation without offering any language choice or documenting that the skill is intended for a Chinese-only context. The policy requires avoiding forced language/locale constraints unless the user can opt in or the limitation is clearly justified.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script silently rewrites the OpenClaw browser configuration to set ssrfPolicy.dangerouslyAllowPrivateNetwork to true, which weakens protections against requests to internal/private network resources. In an agent/browser-automation context, this can enable access to localhost or internal services through browser-driven workflows, materially increasing SSRF-style abuse risk beyond what the script’s description suggests.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file's docstring and all console messages are written only in Chinese, which imposes a specific language on users without any opt-in or alternative locale handling. This is a natural-language policy concern because the skill does not offer language selection or document a justified region-specific constraint.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script accepts the output filename from process.argv[2] and later interpolates it into shell command strings in the system-zip fallback. An attacker supplying a crafted filename containing shell metacharacters or path manipulation can execute arbitrary commands or write archives to unintended locations, especially on macOS/Linux where the string is passed to a shell via exec(). The skill context makes this more dangerous because packaging utilities are often run locally by developers with significant filesystem access.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The fallback packaging path builds a shell command string and executes it with child_process.exec(). Because command construction incorporates runtime-controlled values and passes them through a shell, it creates command-injection risk if an attacker can influence the output filename or execution environment. In a packaging script, this is unnecessary exposure because ZIP creation can be done without invoking a shell.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file's natural-language strings, including the header comment and all console output, are written in Chinese only. This imposes a specific language on users without any opt-in, fallback, or documented region-specific justification, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script takes a user-controlled version argument and interpolates it directly into shell commands executed via child_process.exec for both PowerShell and zip invocation. Because exec invokes a shell, a crafted version string containing shell metacharacters can break out of the intended filename context and execute arbitrary commands on the host running the packaging script.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script launches Chrome with the DevTools remote debugging interface enabled, but it does not warn users that this can expose browser state, cookies, local files, and powerful browser control capabilities to any process or host that can reach the debugging port. Although it prints a localhost URL, the code does not validate the port input, restrict exposure beyond Chrome defaults, or explain the security implications of running a debug-enabled browser profile.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/start-chrome.js (reported line 64)May include surrounding context.

js
console.error('   或使用:which "Google Chrome"');
    } else {
      console.error('   确认 Chrome 已安装:which google-chrome');
      console.error('   或使用:sudo apt install google-chrome-stable');
    }
    process.exit(1);
  }

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script's natural-language interface, comments, usage text, status messages, and recommendations are all presented in Chinese, with no indication that users can select another language or locale. This is a language/locale policy concern because the skill imposes a specific language on all users without opt-in or documented justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The file content, headings, instructions, and warnings are all presented only in Chinese. Under the language/locale policy, forcing a specific language without user opt-in or documented justification can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill documentation is written entirely in Chinese (本地 Chrome 调试模式浏览器自动化配置技能) and provides no indication that another language is available or that the skill is intended only for a Chinese-speaking audience. The policy requires avoiding forced language/locale constraints unless the user is given a choice or the restriction is clearly justified.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/package.js:85

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/setup.js:21

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/simple-package.js:40

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/start-chrome.js:52

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/stop-chrome.js:96

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/troubleshoot.js:72