Back to skill

Security audit

Web Auto Analyzer

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly does what it claims, but it should be reviewed because it audits arbitrary URLs with an unsandboxed Chrome instance and can reach internal/local network targets while saving detailed reports.

Install only if you are comfortable running a local Lighthouse tool against URLs you choose. Do not audit untrusted, authenticated, localhost, private-network, or cloud-metadata URLs unless the browser is isolated. Review the generated reports before sharing them, and avoid copying the sudo, apt-key, process-kill, or package.json overwrite commands into important environments without adapting them safely.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
automation-script.js:32
Finding

Unrestricted Target URL Permits Internal Network Access

Content
View full analysis
!arg.startsWith('--')); const mobile = args.includes('--mobile'); const outputArg = args.find(arg => arg.startsWith('--output=')); const outputDir = outputArg ? outputArg.split('=')[1] : './results'; if (!url) { console.error('❌ Error: URL is required'); process.exit(1); } try { // Run audit const results = await runLighthouseAudit(url, { mobile }); ``` ### Technical Analysis The command-line target is passed directly to Lighthouse without validating its URL scheme, hostname, resolved IP address, or redirect destinations. There are no restrictions preventing access to: - Loopback addresses such as `127.0.0.1` or `::1` - RFC 1918 private networks - Link-local addresses - Internal D ...[truncated 2217 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
automation-script.js:45
Finding

Chrome Sandbox Is Disabled for Untrusted Website Audits

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
Findings (21)

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

The skill description understates its actual capabilities: it not only analyzes a URL but also launches headless Chrome to access remote content and writes JSON/HTML reports to local storage. That mismatch matters because users or orchestrators may grant or invoke the skill without realizing it performs browsing and filesystem writes, which can expose sensitive internal URLs, authenticated pages, or local report data.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 34)May include surrounding context.

md
| Automation script | `automation-script.js` |

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · audit-checklist.md (reported line 73)May include surrounding context.

2. Add Image Alt Text:

html
<!-- Before -->
<img src="product.jpg">

<!-- After -->

Chaining Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

The pipeline wget ... | sudo apt-key add - is a classic chaining-abuse pattern: unverified network content is immediately consumed by a privileged command that alters system trust. In CI/CD context this is more dangerous because runners often have repository secrets, artifact publishing rights, or organizational network access, so a compromised key-import step can enable malicious package installation and broader supply-chain compromise.

Content

Scanner excerpt · troubleshooting.md (reported line 348)May include surrounding context.

md
- name: Install Chrome
        run: |
          wget -q -O - https://dl-ssl.google.com/linux/linux_signing_key.pub | sudo apt-key add -
          sudo sh -c 'echo "deb http://dl.google.com/linux/chrome/deb/ stable main" >> /etc/apt/sources.list.d/google-chrome.list'
          sudo apt-get update
          sudo apt-get install -y google-chrome-stable

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The script performs a Lighthouse audit against the provided URL, which necessarily makes network requests and transmits system/browser request data to the target site. While the script logs that an audit is starting, it does not warn the user that analyzing a URL will contact that site and may expose local IP, headers, or other browser-generated metadata.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The troubleshooting step echo '{"type": "module"}' > package.json will overwrite any existing package.json without warning, destroying project metadata, scripts, dependency declarations, and lockstep configuration. In this skill context, users are explicitly told to run commands in a project directory, so the destructive effect is realistic and can break the project or cause follow-on unsafe recovery actions.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · quick-start.md (reported line 165)May include surrounding context.

md
# Install Chrome
# Ubuntu/Debian:
wget -q https://dl.google.com/linux/direct/google-chrome-stable_current_amd64.deb
sudo dpkg -i google-chrome-stable_current_amd64.deb

# Or use Puppeteer's bundled Chromium:
npm install puppeteer

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · troubleshooting.md (reported line 350)May include surrounding context.

md
# Install Chrome
# Ubuntu/Debian:
wget -q https://dl.google.com/linux/direct/google-chrome-stable_current_amd64.deb
sudo dpkg -i google-chrome-stable_current_amd64.deb

# Or use Puppeteer's bundled Chromium:
npm install puppeteer

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · troubleshooting.md (reported line 351)May include surrounding context.

md
# Install Chrome
# Ubuntu/Debian:
wget -q https://dl.google.com/linux/direct/google-chrome-stable_current_amd64.deb
sudo dpkg -i google-chrome-stable_current_amd64.deb

# Or use Puppeteer's bundled Chromium:
npm install puppeteer

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · setup.md (reported line 334)May include surrounding context.

bash
# Ubuntu/Debian
wget https://dl.google.com/linux/direct/google-chrome-stable_current_amd64.deb
sudo dpkg -i google-chrome-stable_current_amd64.deb

# macOS
open https://www.google.com/chrome/

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · setup.md (reported line 350)May include surrounding context.

bash
# Ubuntu/Debian
wget https://dl.google.com/linux/direct/google-chrome-stable_current_amd64.deb
sudo dpkg -i google-chrome-stable_current_amd64.deb

# macOS
open https://www.google.com/chrome/

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · troubleshooting.md (reported line 65)May include surrounding context.

bash
# Ubuntu/Debian
wget https://dl.google.com/linux/direct/google-chrome-stable_current_amd64.deb
sudo dpkg -i google-chrome-stable_current_amd64.deb

# macOS
open https://www.google.com/chrome/

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · troubleshooting.md (reported line 101)May include surrounding context.

bash
# Ubuntu/Debian
wget https://dl.google.com/linux/direct/google-chrome-stable_current_amd64.deb
sudo dpkg -i google-chrome-stable_current_amd64.deb

# macOS
open https://www.google.com/chrome/

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
93% confidence
Finding

The GitHub Actions example pipes a downloaded signing key directly into sudo apt-key add -, combining network retrieval with privileged trust-store modification. This pattern is risky because it trusts live remote content without verification, and apt-key is deprecated; compromise of the download source or transport chain could let an attacker add a malicious package-signing key and influence subsequent package installs.

Content

Scanner excerpt · troubleshooting.md (reported line 348)May include surrounding context.

md
- name: Install Chrome
        run: |
          wget -q -O - https://dl-ssl.google.com/linux/linux_signing_key.pub | sudo apt-key add -
          sudo sh -c 'echo "deb http://dl.google.com/linux/chrome/deb/ stable main" >> /etc/apt/sources.list.d/google-chrome.list'
          sudo apt-get update
          sudo apt-get install -y google-chrome-stable

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
78% confidence
Finding

sudo sh -c 'echo "deb ..." >> /etc/apt/sources.list.d/google-chrome.list' performs privileged modification of APT sources. While common in setup docs, adding repositories through a root shell increases risk if copied blindly, especially when paired with an externally fetched key, because it expands the trusted software supply chain on the runner.

Content

Scanner excerpt · troubleshooting.md (reported line 349)May include surrounding context.

md
- name: Install Chrome
        run: |
          wget -q -O - https://dl-ssl.google.com/linux/linux_signing_key.pub | sudo apt-key add -
          sudo sh -c 'echo "deb http://dl.google.com/linux/chrome/deb/ stable main" >> /etc/apt/sources.list.d/google-chrome.list'
          sudo apt-get update
          sudo apt-get install -y google-chrome-stable

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The checklist uses <html lang="en"> and <html lang="en-US"> as the prescribed fixes, which can imply a default English locale rather than a user- or site-appropriate language choice. Because SQP-3 applies to natural-language policy constraints across all file types, this is a minor locale-policy concern in instructional content.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The markdown explicitly includes 'Analyzing competitor websites' as a use case, which involves collecting and storing third-party website analysis data, but the surrounding guidance does not warn users about potential data handling, retention, or sensitivity considerations for externally sourced analysis records. Although the file later mentions asking before 'Sharing data externally,' it does not disclose any caution about storing or maintaining competitor-related data in memory.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
92% confidence
Finding

The dependency uses a caret range, so installs may resolve to different future releases rather than a single reviewed version. This weakens build reproducibility and can unintentionally introduce vulnerable or malicious upstream changes into the skill's execution environment.

Content

Scanner excerpt · package.json (reported line 12)May include surrounding context.

json
"test": "node automation-script.js https://example.com"
  },
  "dependencies": {
    "chrome-launcher": "^1.2.1",
    "lighthouse": "^12.8.2"
  }
}

Unverifiable Dependency: chrome-launcher has 1 known advisory(ies) (CVE-2020-7645 (chrome-launcher subject to OS Command Injection)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
72% confidence
Finding

The manifest references chrome-launcher without pinning an exact version, and the package has a known historical command-injection advisory. Because the resolved installed version is not fixed here, it cannot be verified from the manifest alone whether deployments avoid the affected release range, creating a credible risk in a package that launches browser processes.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
92% confidence
Finding

The lighthouse dependency is not pinned to an exact version, which allows different installations to pull different package contents over time. In an automation skill that analyzes arbitrary websites, this increases supply-chain risk and makes security review and incident reproduction harder.

Content

Scanner excerpt · package.json (reported line 13)May include surrounding context.

json
},
  "dependencies": {
    "chrome-launcher": "^1.2.1",
    "lighthouse": "^12.8.2"
  }
}

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The troubleshooting guidance suggests broad process-kill commands such as pkill -f chrome, pkill -f chromium, killall "Google Chrome", and taskkill /F /IM chrome.exe without warning that they may terminate all matching browser processes. In an automation/troubleshooting context this is not inherently malicious, but it can cause unintended disruption, data loss in active browser sessions, or interruption of unrelated workloads on the host.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.