Back to skill

Security audit

God of all Browsers

Security checks for vulnerabilities and agentic risk

Overview

This browser automation skill is powerful and partly disclosed, but it stores login/session data and can run arbitrary scripts in a persistent browser with weak containment.

Review carefully before installing. Use only in an isolated environment with a disposable browser profile, avoid logging into sensitive accounts, do not run eval scripts from untrusted sources, treat session.json and recordings as secrets, clear chrome_profile/session.json/recordings after use, and update or constrain the Puppeteer dependency chain before relying on it.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
browser.js:462
Finding

Sensitive Form Values Are Persisted in Snapshot Artifacts

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
browser.js:800
Finding

Authentication Cookies Are Exported and Retained in Plaintext

Content
View full analysis
!c.domain.includes(currentDomain)); allCookies.push(...newCookies); fs.writeFileSync(sessionPath, JSON.stringify(allCookies, null, 2)); hardenFile(sessionPath); console.log(`💾 Merged and saved cookies to session.json. Total session cookies: ${allCookies.length}`); console.log(`🔒 SECURITY: Ensure session.json is protected. It contains plain-text credentials.`); ``` ### Technical Analysis The `save-session` command exports all cookies available through Puppeteer for the active page and writes them to `session.json` as plaintext JSON. This can include HttpOnly authentication cookies that are not accessible to ordinary page JavaScript but are available through the browser automation API. The code applies mode `0600` on non-Windows systems through `hardenFile()`, which reduces exposure to other local accounts but does not encrypt the credentials. No equivalent Windows ACL hardening is implemented. Any process operating as the same user, malware, an exposed backup, or an accidentally published project directory can still recover the cookies. Cookies from multiple domains are accumulated in the same file, increasing the potential blast radius of a single file disclosure. The persistent `chrome_profile` directory separately retains browser sessions, so plaintext cookie export is not strictly required for the declared stateful-browser funct ...[truncated 1137 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
browser.js:893
Finding

Arbitrary Page-Context JavaScript Can Access Authenticated Data and Use Network Channels

Content
View full analysis
{ try { // Use AsyncFunction constructor for a cleaner execution environment support for await. // This is an intentional feature of "GOD OF ALL BROWSERS" for automation power-users. const AsyncFunction = Object.getPrototypeOf(async function () { }).constructor; return await (new AsyncFunction(codeStr))(); ...[truncated 2687 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
browser.js:121
Finding

Chromium Sandbox Is Disabled by Default on Non-Windows Platforms

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (34)

YARA rule 'info_stealer': Information stealer patterns (credential harvesting, browser data theft) [malware]

High
Category
YARA Match
Confidence
89% confidence
Finding

The skill intentionally preserves browser profiles, cookies, and local storage and supports exporting session material to plaintext session.json, which creates credential-like artifacts that can be stolen or misused. Combined with bot-evasion features and browser automation, this substantially increases the risk of account/session takeover and covert data extraction if the tool or its outputs are accessed by an untrusted agent or user.

Content

Scanner excerpt · README.md (reported line 139)May include surrounding context.

md
`session.json`: Exported cookie/session data.
- `recordings/`: Snapshots and screenshots for manual review.

---

## 🛡️ Security & Ethics

`God of all Browsers` is a powerful tool designed for responsible automation. Users should be aware of the following security considerations:

### 1. **Data Persistence**
*   **Persistent Profiles**: By default, this tool saves all session data, cookies, and local storage in the `./chrome_profile/` directory. This is intentional to allow stateful AI workflows.
*   **Cookie Export**: The `save-session` command exports cookies to `session.json` in plain text. Always treat this file as a sensitive credential.

### 2. **Arbitrary Code Execution (`eval`)**
*   The `eval` command is a high-risk feature that allows executing arbitrary JavaScript inside the browser context. Only use scripts from trusted sources and monitor agent-generated scripts for potential data exfiltration.

### 3. **Bot Evasion & Ethics**
*   Built-in evasion tec

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The description frames the skill as browser automation, but the documented commands include arbitrary JavaScript execution in page context, loading script files from disk, persistent session export, and broad artifact/log generation. This mismatch is dangerous because reviewers or orchestration systems may grant trust appropriate for navigation automation while overlooking code execution, sensitive session handling, and data exfiltration paths.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The description frames the skill as browser automation, but the documented commands include arbitrary JavaScript execution in page context, loading script files from disk, persistent session export, and broad artifact/log generation. This mismatch is dangerous because reviewers or orchestration systems may grant trust appropriate for navigation automation while overlooking code execution, sensitive session handling, and data exfiltration paths.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The description frames the skill as browser automation, but the documented commands include arbitrary JavaScript execution in page context, loading script files from disk, persistent session export, and broad artifact/log generation. This mismatch is dangerous because reviewers or orchestration systems may grant trust appropriate for navigation automation while overlooking code execution, sensitive session handling, and data exfiltration paths.

Content

No source excerpt is available for this finding.

YARA rule 'info_stealer': Information stealer patterns (credential harvesting, browser data theft) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · browser.js (reported line 160)May include surrounding context.

js
newly started browser or navigate to URL.", err instanceof Error ? err.message : err);
        } finally {
            if (browserInstance) {
                // await browserInstance.disconnect(); // Disconnecting is not necessary as the script exits.
            }
        }

        console.log("🚀 GOD OF ALL BROWSERS started in the background (Port 10087)!");
        console.log("Your cookies/session are natively stored in 'chrome_profile' folder.");
        process.exit(0);
    }

    let browser;
    try {
        browser = await puppeteer.connect({
            browserURL: `http://127.0.0.1:${DEBUG_PORT}`,
            defaultViewport: null,
            protocolTimeout: 1800000 // 30 minutes
        });
    } catch (e) {
        console.error(`❌ GOD OF ALL BROWSERS is not running on Port ${DEBUG_PORT}. Please run 'node browser.js start' first.`);
        return;
    }

    if (command === 'stop') {
        await browser.close();
        if (fs.existsSyn

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The eval command executes arbitrary JavaScript in the context of whatever page is open, using either inline code or a file. In a browser automation skill that stores persistent cookies and can read page data, this creates a powerful capability for credential theft, session hijacking, DOM scraping, and unauthorized actions on authenticated sites; the --force flag is only a usability gate, not a real security control.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: basic-ftp==5.2.0 — 4 advisory(ies): GHSA-6v7q-wjvx-w8wg (basic-ftp: Incomplete CRLF Injection Protection Allows Arbitrary FTP Command Exe); CVE-2026-39983 (basic-ftp has FTP Command Injection via CRLF); CVE-2026-41324 (basic-ftp vulnerable to denial of service via unbounded memory consumption in Cl) +1 more

High
Category
Supply Chain
Confidence
96% confidence
Finding

The lockfile pins basic-ftp 5.2.0, which is reported to have FTP command injection and denial-of-service issues. In this dependency graph it is pulled in transitively via get-uri/pac-proxy-agent/proxy-agent rather than being an explicit FTP feature of the skill, so exploitation depends on the application accepting attacker-controlled FTP/PAC URLs or proxy configuration; that makes it a real but context-dependent supply-chain risk.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: extract-zip==2.0.1 — 2 advisory(ies): CVE-2026-19693 (extract-zip allows arbitrary file writes through symlink archive entries); CVE-2026-56876 (extract-zip unvalidated symlink path traversal)

High
Category
Supply Chain
Confidence
98% confidence
Finding

extract-zip 2.0.1 is present and is associated with arbitrary file write/path traversal via symlink handling during archive extraction. Here it is included through @puppeteer/browsers, which may download and extract browser binaries; if an attacker can influence the downloaded archive or extraction source, this could lead to filesystem overwrite during setup/update operations.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: ip-address==10.1.0 — 2 advisory(ies): CVE-2026-69192 (ip-address: Address4 decodes leading-zero octets as decimal while resolvers deco); CVE-2026-42338 (ip-address has XSS in Address6 HTML-emitting methods)

High
Category
Supply Chain
Confidence
84% confidence
Finding

ip-address 10.1.0 is flagged for ambiguous parsing and XSS in HTML-emitting methods. In this lockfile it is a transitive dependency of socks, used by proxy support; unless the skill exposes attacker-controlled address parsing logic or renders Address6 HTML output, practical exploitability is limited, but the vulnerable package is still present.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: ws==8.19.0 — 2 advisory(ies): CVE-2026-45736 (ws: Uninitialized memory disclosure); CVE-2026-48779 (ws: Memory exhaustion DoS from tiny fragments and data chunks)

High
Category
Supply Chain
Confidence
95% confidence
Finding

ws 8.19.0 is included through puppeteer-core and is reported vulnerable to memory disclosure and memory-exhaustion denial of service. Because this skill is a browser automation tool that may communicate with browser/debugging endpoints over WebSocket, the presence of a vulnerable WebSocket library is more relevant than in a passive package and could increase risk if untrusted endpoints can connect or be connected to.

Content

No source excerpt is available for this finding.

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · setup.sh (reported line 25)May include surrounding context.

sh
if [ ! -f "/usr/bin/chromium" ]; then
    echo -e "${BLUE}Warning: /usr/bin/chromium not found.${NC}"
    echo -e "To use God of all Browsers on Linux, please install Chromium manually:"
    echo -e "  sudo apt update && sudo apt install -y chromium-browser"
    echo -e "Once installed, ensure it is at /usr/bin/chromium"
fi

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The eval command explicitly allows execution of arbitrary JavaScript in the browser context, which is broader than normal browser automation and can be used to access page data, session state, DOM contents, and authenticated resources. In an AI-agent skill, this is especially dangerous because model-generated or user-supplied scripts could exfiltrate sensitive data or perform unintended privileged actions using the persistent logged-in browser session.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
96% confidence
Finding

The skill exposes browser automation capabilities that inherently touch the network and environment, but the manifest does not declare any explicit tool scope or permission boundaries. In an agent setting, this creates an under-specified trust boundary: callers may invoke a skill that can reach external sites, persist state, and interact with local files without clear policy constraints.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill is described in broad, promotional terms without clear activation constraints or safe-use boundaries. In an agent ecosystem, ambiguous invocation criteria can cause over-selection of a powerful browser skill for tasks that do not require it, increasing exposure to unnecessary network access, session persistence, and high-risk automation behaviors.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill promotes permanent cookie and session persistence without clearly warning that authentication state and tracking artifacts may be stored on disk. In practice, this can expose account sessions to other local processes, future tasks, or unauthorized reuse, especially in shared or multi-tenant environments.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Automatically clicking away popups without user review can dismiss consent dialogs, accept terms, reject or accept privacy choices, or trigger unintended actions on transactional sites. Because the skill targets heavily protected websites and aims to mimic humans, silent interaction with consent surfaces is especially risky and can create legal, privacy, or account-state consequences.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documented eval feature expands the skill from browser automation into a general-purpose in-page code execution tool. In context, that means an agent can run arbitrary DOM-accessing JavaScript on authenticated pages, collect sensitive data, alter state, and combine that with persistent cookies and disk storage, materially increasing abuse potential.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The custom JavaScript execution feature is documented with examples but without adequate warning that it can read sensitive DOM data, mutate authenticated pages, trigger actions, and combine with persistent sessions for powerful abuse. The presence of a --force flag helps, but it is not a sufficient safeguard when the skill is used by autonomous agents or less-aware operators.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The session-saving guidance explicitly instructs saving cookies to session.json but does not warn that authentication tokens may be written to disk and reused later. This creates a clear risk of credential/session theft, privilege carryover across tasks, and inadvertent retention of sensitive account state.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The inline documentation claims that hoisting reads of environment variables and files to top level is a security hardening step that breaks dynamic flow analysis between untrusted sources and sensitive sinks. However, the values from process.env and debug_port.txt are still used to configure the browser debugging endpoint, so the comment asserts a security property that the code does not actually enforce.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The code claims the randomized remote debugging port secures the attack surface, but it persists the port to disk and reconnects to it later, while also printing a misleading fixed-port message. Remote debugging exposes full browser control, so treating obscurity and on-disk discoverability as a security boundary is unsafe and can enable local compromise by any process or user able to read the file or connect locally.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The snapshot feature writes structured page content and screenshots to disk, which may include tokens, account data, messages, PII, or confidential business information from authenticated pages. Because this skill is explicitly designed to preserve sessions and browse real sites, silent local data retention materially increases exposure if the host is shared or compromised.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

After filling a field, the tool automatically presses Enter, which can submit forms, trigger purchases, send messages, approve prompts, or otherwise commit actions the operator did not explicitly request. In an authenticated browser with persistent sessions, this increases the chance of unintended state-changing operations on sensitive sites.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The read command extracts DOM content and prints it directly to stdout, including content from frames when available. This can expose secrets, account details, internal documents, or personal data into logs, terminal history, calling systems, or downstream agents without any sensitivity checks or warning.

Content

No source excerpt is available for this finding.

Unrestricted Tool Access

Medium
Category
Excessive Agency
Confidence
98% confidence
Finding

This finding is the same core issue as the eval command: the skill intentionally provides unrestricted arbitrary script execution against the live browser session. Given persistent cookies, page access, and the ability to issue network requests from page context, this is effectively unrestricted tool access over authenticated browser state.

Content

Scanner excerpt · browser.js (reported line 897)May include surrounding context.

js
// SECURITY GATE: Require explicit confirmation for arbitrary code execution.
            if (!args.includes('--force') && process.env.GOD_AUTO_EVAL !== 'true') {
                console.error("❌ SECURITY GATE: Usage of 'eval' requires the '--force' flag or 'GOD_AUTO_EVAL=true' environment variable.");
                console.error("This is an intentional safety guard because 'eval' can execute arbitrary scripts.");
                console.error("\nUsage: node browser.js eval --code '...' --force");
                return;
            }

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
browser.js:136