Back to skill

Security audit

Brave Browser Agent

Security checks for vulnerabilities and agentic risk

Overview

This skill openly provides Brave browser automation, but it connects to the user's logged-in daily browser and includes under-scoped sensitive extraction, publishing, and anti-detection automation guidance.

Install only if you are comfortable giving an agent control over your currently logged-in Brave session. Prefer a separate temporary Brave profile with no personal logins, use an explicit tab/origin allowlist, avoid cookie/storage/form dumps, and require manual confirmation before screenshots, JavaScript eval, clicks, form submissions, publishing actions, or automation on sites with anti-bot controls.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:9
Finding

<![CDATA[The Skill attaches to the user's daily authenticated browser profile]]>

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
references/PATTERNS.md:175
Finding

<![CDATA[Documentation explicitly enables extraction of cookies, browser storage, and form values]]>

Content
View full analysis
"Array.from(document.querySelectorAll('input, select, textarea')).map(el => ({name: el.name, value: el.value, type: el.type}))" ``` ### Get Page Cookies ```bash python3 {{SKILL_DIR}}/scripts/cdp_exec.py eval "document.cookie" ``` ### Get Local Storage ```bash python3 {{SKILL_DIR}}/scripts/cdp_exec.py eval "JSON.stringify({...localStorage})" ``` ### Get Session Storage ```bash python3 {{SKILL_DIR}}/scripts/cdp_exec.py eval "JSON.stringify({...sessionStorage})" ``` ``` ### Technical Analysis These documented commands encourage unrestricted collection of form values and origin-scoped browser storage from authenticated pages. Form-value enumeration includes all `input`, `select`, and `textarea` elements without excluding password fields, hidden anti-CSRF fields, private drafts, personal information, or payment-related values. Cookies accessible through `document.cookie` and values stored in `localStorage` or `sessionStorage` may contain authentication tokens, bearer tokens, user identifiers, application state, or other sensitive information. `HttpOnly` cookies are not accessible through `document.cookie`, which limits this specific command. However, many applications store valuable session or API material in JavaScript-accessible storage. No code was found that automatically transmits this data to an external server. The immediate exposure channel is command output, which can still place secrets in agent context, terminal history, logs, or subsequent tool calls. ### Attack Path 1. The Skill enumerates tabs in the user's authenticated daily browser. 2. A target tab is selected for a service holding session or ...[truncated 768 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/smart_interact.py:207
Finding

<![CDATA[CLI-controlled selectors and text are unsafely interpolated into JavaScript]]>

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:246
Finding

<![CDATA[Third-party WebSocket dependency is installed without version or integrity constraints]]>

Content
View full analysis
Remediation
View remediation
--hash=sha256: ``` 3. Install with `pip install --require-hashes -r requirements.txt`. 4. Provide a lockfile generated from a trusted package source. 5. Use a project-specific virtual environment rather than the global Python environment. 6. Document the expected package index and avoid untrusted mirrors. 7. Periodically review and update the pinned version after security testing. 8. Consider packaging the Skill with declared, reproducible dependencies instead of runtime installation instructions. ]]>
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (42)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared description presents a full Brave CDP automation skill, but the supplied code chunk is only a diagnostic utility that verifies CDP availability and enumerates tabs. Its primary purpose is status checking, not browser control. While checking the CDP endpoint is related support functionality, this code chunk does not implement the main declared capabilities and therefore materially differs from the description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description presents the skill as an operational Brave CDP automation tool for browsing and page interaction. The supplied code chunk instead functions as a diagnostic utility for that skill/environment. It connects to the local CDP endpoint and enumerates tabs, but its main work is checking local files and metadata: parsing sibling scripts for syntax, validating SKILL.md headings/template usage, and counting assets. Those are materially different from the declared end-user capabilities. While using Brave on port 9222 is consistent with the description, the code shown does not implement the advertised browser automation actions such as content extraction, screenshots, or JavaScript execution. Therefore the description does not accurately represent this code chunk.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly attaches to the user's daily browser session with active logins, bookmarks, and tabs, enabling access to highly sensitive authenticated content. Because the documentation does not prominently require informed consent or warn about privacy exposure, an agent could inspect or extract personal data from an already-authenticated session unexpectedly.

Content

No source excerpt is available for this finding.

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · references/site-patterns.md (reported line 14)May include surrounding context.

md
1. **Use `detail_url` from search results** — contains `xsec_token` required for navigation
2. **Never navigate to `/explore/<id>` directly** — redirects to homepage
3. **Use CDP `Input.dispatchMouseEvent`** for clicking — `isTrusted=true`, bypasses detection
4. **`cdp_exec.py open` returns 405** — use `curl -X PUT` or `eval` navigation instead

### Search → Extract → Detail Workflow

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill exposes powerful capabilities through shell, network, file access, and environment use, but it does not declare any explicit tool scope or permission boundaries. That makes it harder for a host system or reviewer to enforce least privilege and increases the chance the skill is invoked with broader access than users expect.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The activation language is broad enough to trigger this skill for ordinary browsing or help requests, yet the skill attaches to the user's real logged-in browser and can execute JavaScript and interact with pages. Overbroad routing increases the chance of accidental use in sensitive contexts without informed user intent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The troubleshooting instruction tells the agent to use a fixed Chinese message: 'Brave Browser 未启动远程调试,请手动开启.' This imposes a specific language on user-facing output without indicating that the user prefers Chinese or that the skill is region-specific.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The documented commands include opening pages, closing tabs, executing JavaScript, taking screenshots, and interacting with page elements, all of which can alter browser state or trigger side effects in authenticated sessions. Without explicit warnings and consent checkpoints, users may not realize these actions can submit forms, change account settings, or disrupt their existing browser activity.

Content

No source excerpt is available for this finding.

Ssd 2

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly promotes anti-detection techniques that simulate trusted user interaction to evade bot defenses on third-party sites. That crosses from normal automation into bypass behavior, enabling abuse of platform restrictions, deceptive interaction, and harder-to-detect actions within authenticated sessions.

Content

No source excerpt is available for this finding.

Ssd 2

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The framework-aware click fallbacks describe progressively more invasive techniques to trigger application behavior, including React/Vue internals and synthetic event dispatch designed to overcome normal UI constraints. In the context of a live logged-in browser, these techniques can be used to bypass app-layer safeguards and trigger actions the site did not intend to accept from automation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation explicitly recommends 'anti-detection' interaction methods and labels them as useful for anti-bot sites, which goes beyond neutral browser automation guidance and into evasion-oriented behavior. In a browser-control skill, this increases the likelihood of misuse for bypassing site defenses or automating against platform restrictions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The fetch example demonstrates arbitrary network requests from the browser context without explaining privacy, data-handling, or external transfer implications. In a browser automation skill, this can be repurposed to exfiltrate page-derived or browser-resident data to remote endpoints.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/PATTERNS.md (reported line 139)May include surrounding context.

Fetch API Data

bash
python3 {{SKILL_DIR}}/scripts/cdp_exec.py eval <tab_id> "fetch('https://api.example.com/data').then(r => r.json())" --await-promise

Scroll to Load More Content

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The examples show how to read cookies and local/session storage without any warning that these stores may contain authentication tokens, session identifiers, or other sensitive user data. In a browser agent context, documenting these access patterns without safeguards can enable credential/session theft or privacy violations.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Referencing site-specific anti-detection strategies and 'verified workflows' for named platforms signals tailored guidance for bypassing platform defenses. That narrows the skill from general automation to potentially evasive, target-aware automation, which materially raises abuse potential.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The markdown provides direct publish/click automation recipes for third-party platforms without clear warnings, consent checkpoints, or safeguards around content submission. In this skill's context, the commands are specifically oriented toward publishing workflows, so omission of strong warnings and confirmation requirements materially raises the chance of accidental or unauthorized posting/modification of user content.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation explicitly promotes bypassing normal browser interaction by directly invoking framework event handlers such as React/Vue click callbacks. In a browser automation skill, this can trigger privileged site actions like publish, submit, or delete in ways that evade normal UI gating, confirmation flows, or trusted-event checks, increasing the risk of unintended or unauthorized state-changing actions on third-party sites.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

This documentation explicitly teaches anti-detection techniques to evade site controls, including using native CDP events because they produce isTrusted=true interactions and preserving xsec_token values needed for access. That goes beyond ordinary automation guidance and materially enables bypass of platform restrictions, anti-bot defenses, and likely terms-of-service enforcement.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file documents workflows for scraping, extracting comments, and scaling collection patterns without any warning about consent, privacy, authorization, or impact on target sites. In context, the absence of safety constraints makes the anti-detection material more operationally dangerous because it normalizes covert collection from real platforms.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The generic section recommends choosing CDP native events and human-like typing specifically to bypass anti-bot detection, including cases where sites inspect isTrusted. That is generalizable evasion guidance that can be applied broadly across protected sites, increasing abuse potential beyond the named example.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script exposes Runtime.evaluate over CDP, which can execute arbitrary JavaScript inside the selected tab and therefore inspect page contents, session state, or modify the page. Although the function names say 'Execute JS', there is no explicit safety warning or confirmation that this operation can affect user data or page state in the user's daily browser.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The screenshot path captures the current page and saves the resulting image to a local file, which may include sensitive on-screen information. While the code prints the saved filename afterward, it does not warn users beforehand that page contents will be persisted to disk.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest describes a skill for controlling Brave via CDP for browsing, extraction, screenshots, and JavaScript execution. In addition to CDP control, this file invokes separate local Python processes via subprocess.run to handle interaction, page-state, and framework-click features, which is a broader host-level execution capability not justified by the stated browser-focused purpose.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/cdp_exec.py (reported line 440)May include surrounding context.

python
if args.text:
                cmd += ["--text", args.text]
            cmd += ["--index", str(args.index)]
        subprocess.run(cmd)
    elif args.command in ("elements", "pagination", "snapshot", "page-status", "count"):
        # Delegate to page_state.py
        import subprocess, os

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/cdp_exec.py (reported line 456)May include surrounding context.

python
if args.text:
                cmd += ["--text", args.text]
            cmd += ["--index", str(args.index)]
        subprocess.run(cmd)
    elif args.command in ("elements", "pagination", "snapshot", "page-status", "count"):
        # Delegate to page_state.py
        import subprocess, os

Static analysis

No suspicious patterns detected.