T09 · Insecure Skill Coding Practices
- Location
browser.js:462- Finding
Sensitive Form Values Are Persisted in Snapshot Artifacts
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This browser automation skill is powerful and partly disclosed, but it stores login/session data and can run arbitrary scripts in a persistent browser with weak containment.
Review carefully before installing. Use only in an isolated environment with a disposable browser profile, avoid logging into sensitive accounts, do not run eval scripts from untrusted sources, treat session.json and recordings as secrets, clear chrome_profile/session.json/recordings after use, and update or constrain the Puppeteer dependency chain before relying on it.
browser.js:462Sensitive Form Values Are Persisted in Snapshot Artifacts
browser.js:800Authentication Cookies Are Exported and Retained in Plaintext
browser.js:893Arbitrary Page-Context JavaScript Can Access Authenticated Data and Use Network Channels
browser.js:121Chromium Sandbox Is Disabled by Default on Non-Windows Platforms
The skill intentionally preserves browser profiles, cookies, and local storage and supports exporting session material to plaintext session.json, which creates credential-like artifacts that can be stolen or misused. Combined with bot-evasion features and browser automation, this substantially increases the risk of account/session takeover and covert data extraction if the tool or its outputs are accessed by an untrusted agent or user.
`session.json`: Exported cookie/session data.
- `recordings/`: Snapshots and screenshots for manual review.
---
## 🛡️ Security & Ethics
`God of all Browsers` is a powerful tool designed for responsible automation. Users should be aware of the following security considerations:
### 1. **Data Persistence**
* **Persistent Profiles**: By default, this tool saves all session data, cookies, and local storage in the `./chrome_profile/` directory. This is intentional to allow stateful AI workflows.
* **Cookie Export**: The `save-session` command exports cookies to `session.json` in plain text. Always treat this file as a sensitive credential.
### 2. **Arbitrary Code Execution (`eval`)**
* The `eval` command is a high-risk feature that allows executing arbitrary JavaScript inside the browser context. Only use scripts from trusted sources and monitor agent-generated scripts for potential data exfiltration.
### 3. **Bot Evasion & Ethics**
* Built-in evasion tec
The description frames the skill as browser automation, but the documented commands include arbitrary JavaScript execution in page context, loading script files from disk, persistent session export, and broad artifact/log generation. This mismatch is dangerous because reviewers or orchestration systems may grant trust appropriate for navigation automation while overlooking code execution, sensitive session handling, and data exfiltration paths.
The description frames the skill as browser automation, but the documented commands include arbitrary JavaScript execution in page context, loading script files from disk, persistent session export, and broad artifact/log generation. This mismatch is dangerous because reviewers or orchestration systems may grant trust appropriate for navigation automation while overlooking code execution, sensitive session handling, and data exfiltration paths.
The description frames the skill as browser automation, but the documented commands include arbitrary JavaScript execution in page context, loading script files from disk, persistent session export, and broad artifact/log generation. This mismatch is dangerous because reviewers or orchestration systems may grant trust appropriate for navigation automation while overlooking code execution, sensitive session handling, and data exfiltration paths.
YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).
newly started browser or navigate to URL.", err instanceof Error ? err.message : err);
} finally {
if (browserInstance) {
// await browserInstance.disconnect(); // Disconnecting is not necessary as the script exits.
}
}
console.log("🚀 GOD OF ALL BROWSERS started in the background (Port 10087)!");
console.log("Your cookies/session are natively stored in 'chrome_profile' folder.");
process.exit(0);
}
let browser;
try {
browser = await puppeteer.connect({
browserURL: `http://127.0.0.1:${DEBUG_PORT}`,
defaultViewport: null,
protocolTimeout: 1800000 // 30 minutes
});
} catch (e) {
console.error(`❌ GOD OF ALL BROWSERS is not running on Port ${DEBUG_PORT}. Please run 'node browser.js start' first.`);
return;
}
if (command === 'stop') {
await browser.close();
if (fs.existsSyn
The eval command executes arbitrary JavaScript in the context of whatever page is open, using either inline code or a file. In a browser automation skill that stores persistent cookies and can read page data, this creates a powerful capability for credential theft, session hijacking, DOM scraping, and unauthorized actions on authenticated sites; the --force flag is only a usability gate, not a real security control.
The lockfile pins basic-ftp 5.2.0, which is reported to have FTP command injection and denial-of-service issues. In this dependency graph it is pulled in transitively via get-uri/pac-proxy-agent/proxy-agent rather than being an explicit FTP feature of the skill, so exploitation depends on the application accepting attacker-controlled FTP/PAC URLs or proxy configuration; that makes it a real but context-dependent supply-chain risk.
extract-zip 2.0.1 is present and is associated with arbitrary file write/path traversal via symlink handling during archive extraction. Here it is included through @puppeteer/browsers, which may download and extract browser binaries; if an attacker can influence the downloaded archive or extraction source, this could lead to filesystem overwrite during setup/update operations.
ip-address 10.1.0 is flagged for ambiguous parsing and XSS in HTML-emitting methods. In this lockfile it is a transitive dependency of socks, used by proxy support; unless the skill exposes attacker-controlled address parsing logic or renders Address6 HTML output, practical exploitability is limited, but the vulnerable package is still present.
ws 8.19.0 is included through puppeteer-core and is reported vulnerable to memory disclosure and memory-exhaustion denial of service. Because this skill is a browser automation tool that may communicate with browser/debugging endpoints over WebSocket, the presence of a vulnerable WebSocket library is more relevant than in a passive package and could increase risk if untrusted endpoints can connect or be connected to.
Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.
if [ ! -f "/usr/bin/chromium" ]; then
echo -e "${BLUE}Warning: /usr/bin/chromium not found.${NC}"
echo -e "To use God of all Browsers on Linux, please install Chromium manually:"
echo -e " sudo apt update && sudo apt install -y chromium-browser"
echo -e "Once installed, ensure it is at /usr/bin/chromium"
fi
The eval command explicitly allows execution of arbitrary JavaScript in the browser context, which is broader than normal browser automation and can be used to access page data, session state, DOM contents, and authenticated resources. In an AI-agent skill, this is especially dangerous because model-generated or user-supplied scripts could exfiltrate sensitive data or perform unintended privileged actions using the persistent logged-in browser session.
The skill exposes browser automation capabilities that inherently touch the network and environment, but the manifest does not declare any explicit tool scope or permission boundaries. In an agent setting, this creates an under-specified trust boundary: callers may invoke a skill that can reach external sites, persist state, and interact with local files without clear policy constraints.
The skill is described in broad, promotional terms without clear activation constraints or safe-use boundaries. In an agent ecosystem, ambiguous invocation criteria can cause over-selection of a powerful browser skill for tasks that do not require it, increasing exposure to unnecessary network access, session persistence, and high-risk automation behaviors.
The skill promotes permanent cookie and session persistence without clearly warning that authentication state and tracking artifacts may be stored on disk. In practice, this can expose account sessions to other local processes, future tasks, or unauthorized reuse, especially in shared or multi-tenant environments.
Automatically clicking away popups without user review can dismiss consent dialogs, accept terms, reject or accept privacy choices, or trigger unintended actions on transactional sites. Because the skill targets heavily protected websites and aims to mimic humans, silent interaction with consent surfaces is especially risky and can create legal, privacy, or account-state consequences.
The documented eval feature expands the skill from browser automation into a general-purpose in-page code execution tool. In context, that means an agent can run arbitrary DOM-accessing JavaScript on authenticated pages, collect sensitive data, alter state, and combine that with persistent cookies and disk storage, materially increasing abuse potential.
The custom JavaScript execution feature is documented with examples but without adequate warning that it can read sensitive DOM data, mutate authenticated pages, trigger actions, and combine with persistent sessions for powerful abuse. The presence of a --force flag helps, but it is not a sufficient safeguard when the skill is used by autonomous agents or less-aware operators.
The session-saving guidance explicitly instructs saving cookies to session.json but does not warn that authentication tokens may be written to disk and reused later. This creates a clear risk of credential/session theft, privilege carryover across tasks, and inadvertent retention of sensitive account state.
The inline documentation claims that hoisting reads of environment variables and files to top level is a security hardening step that breaks dynamic flow analysis between untrusted sources and sensitive sinks. However, the values from process.env and debug_port.txt are still used to configure the browser debugging endpoint, so the comment asserts a security property that the code does not actually enforce.
The code claims the randomized remote debugging port secures the attack surface, but it persists the port to disk and reconnects to it later, while also printing a misleading fixed-port message. Remote debugging exposes full browser control, so treating obscurity and on-disk discoverability as a security boundary is unsafe and can enable local compromise by any process or user able to read the file or connect locally.
The snapshot feature writes structured page content and screenshots to disk, which may include tokens, account data, messages, PII, or confidential business information from authenticated pages. Because this skill is explicitly designed to preserve sessions and browse real sites, silent local data retention materially increases exposure if the host is shared or compromised.
After filling a field, the tool automatically presses Enter, which can submit forms, trigger purchases, send messages, approve prompts, or otherwise commit actions the operator did not explicitly request. In an authenticated browser with persistent sessions, this increases the chance of unintended state-changing operations on sensitive sites.
The read command extracts DOM content and prints it directly to stdout, including content from frames when available. This can expose secrets, account details, internal documents, or personal data into logs, terminal history, calling systems, or downstream agents without any sensitivity checks or warning.
This finding is the same core issue as the eval command: the skill intentionally provides unrestricted arbitrary script execution against the live browser session. Given persistent cookies, page access, and the ability to issue network requests from page context, this is effectively unrestricted tool access over authenticated browser state.
// SECURITY GATE: Require explicit confirmation for arbitrary code execution.
if (!args.includes('--force') && process.env.GOD_AUTO_EVAL !== 'true') {
console.error("❌ SECURITY GATE: Usage of 'eval' requires the '--force' flag or 'GOD_AUTO_EVAL=true' environment variable.");
console.error("This is an intentional safety guard because 'eval' can execute arbitrary scripts.");
console.error("\nUsage: node browser.js eval --code '...' --force");
return;
}
Detected: suspicious.dangerous_exec