T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:9- Finding
<![CDATA[The Skill attaches to the user's daily authenticated browser profile]]>
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill openly provides Brave browser automation, but it connects to the user's logged-in daily browser and includes under-scoped sensitive extraction, publishing, and anti-detection automation guidance.
Install only if you are comfortable giving an agent control over your currently logged-in Brave session. Prefer a separate temporary Brave profile with no personal logins, use an explicit tab/origin allowlist, avoid cookie/storage/form dumps, and require manual confirmation before screenshots, JavaScript eval, clicks, form submissions, publishing actions, or automation on sites with anti-bot controls.
SKILL.md:9<![CDATA[The Skill attaches to the user's daily authenticated browser profile]]>
references/PATTERNS.md:175<![CDATA[Documentation explicitly enables extraction of cookies, browser storage, and form values]]>
scripts/smart_interact.py:207<![CDATA[CLI-controlled selectors and text are unsafely interpolated into JavaScript]]>
SKILL.md:246<![CDATA[Third-party WebSocket dependency is installed without version or integrity constraints]]>
The declared description presents a full Brave CDP automation skill, but the supplied code chunk is only a diagnostic utility that verifies CDP availability and enumerates tabs. Its primary purpose is status checking, not browser control. While checking the CDP endpoint is related support functionality, this code chunk does not implement the main declared capabilities and therefore materially differs from the description.
The declared description presents the skill as an operational Brave CDP automation tool for browsing and page interaction. The supplied code chunk instead functions as a diagnostic utility for that skill/environment. It connects to the local CDP endpoint and enumerates tabs, but its main work is checking local files and metadata: parsing sibling scripts for syntax, validating SKILL.md headings/template usage, and counting assets. Those are materially different from the declared end-user capabilities. While using Brave on port 9222 is consistent with the description, the code shown does not implement the advertised browser automation actions such as content extraction, screenshots, or JavaScript execution. Therefore the description does not accurately represent this code chunk.
The skill explicitly attaches to the user's daily browser session with active logins, bookmarks, and tabs, enabling access to highly sensitive authenticated content. Because the documentation does not prominently require informed consent or warn about privacy exposure, an agent could inspect or extract personal data from an already-authenticated session unexpectedly.
Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
1. **Use `detail_url` from search results** — contains `xsec_token` required for navigation
2. **Never navigate to `/explore/<id>` directly** — redirects to homepage
3. **Use CDP `Input.dispatchMouseEvent`** for clicking — `isTrusted=true`, bypasses detection
4. **`cdp_exec.py open` returns 405** — use `curl -X PUT` or `eval` navigation instead
### Search → Extract → Detail Workflow
The skill exposes powerful capabilities through shell, network, file access, and environment use, but it does not declare any explicit tool scope or permission boundaries. That makes it harder for a host system or reviewer to enforce least privilege and increases the chance the skill is invoked with broader access than users expect.
The activation language is broad enough to trigger this skill for ordinary browsing or help requests, yet the skill attaches to the user's real logged-in browser and can execute JavaScript and interact with pages. Overbroad routing increases the chance of accidental use in sensitive contexts without informed user intent.
The troubleshooting instruction tells the agent to use a fixed Chinese message: 'Brave Browser 未启动远程调试,请手动开启.' This imposes a specific language on user-facing output without indicating that the user prefers Chinese or that the skill is region-specific.
The documented commands include opening pages, closing tabs, executing JavaScript, taking screenshots, and interacting with page elements, all of which can alter browser state or trigger side effects in authenticated sessions. Without explicit warnings and consent checkpoints, users may not realize these actions can submit forms, change account settings, or disrupt their existing browser activity.
The skill explicitly promotes anti-detection techniques that simulate trusted user interaction to evade bot defenses on third-party sites. That crosses from normal automation into bypass behavior, enabling abuse of platform restrictions, deceptive interaction, and harder-to-detect actions within authenticated sessions.
The framework-aware click fallbacks describe progressively more invasive techniques to trigger application behavior, including React/Vue internals and synthetic event dispatch designed to overcome normal UI constraints. In the context of a live logged-in browser, these techniques can be used to bypass app-layer safeguards and trigger actions the site did not intend to accept from automation.
The documentation explicitly recommends 'anti-detection' interaction methods and labels them as useful for anti-bot sites, which goes beyond neutral browser automation guidance and into evasion-oriented behavior. In a browser-control skill, this increases the likelihood of misuse for bypassing site defenses or automating against platform restrictions.
The fetch example demonstrates arbitrary network requests from the browser context without explaining privacy, data-handling, or external transfer implications. In a browser automation skill, this can be repurposed to exfiltrate page-derived or browser-resident data to remote endpoints.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
python3 {{SKILL_DIR}}/scripts/cdp_exec.py eval <tab_id> "fetch('https://api.example.com/data').then(r => r.json())" --await-promise
The examples show how to read cookies and local/session storage without any warning that these stores may contain authentication tokens, session identifiers, or other sensitive user data. In a browser agent context, documenting these access patterns without safeguards can enable credential/session theft or privacy violations.
Referencing site-specific anti-detection strategies and 'verified workflows' for named platforms signals tailored guidance for bypassing platform defenses. That narrows the skill from general automation to potentially evasive, target-aware automation, which materially raises abuse potential.
The markdown provides direct publish/click automation recipes for third-party platforms without clear warnings, consent checkpoints, or safeguards around content submission. In this skill's context, the commands are specifically oriented toward publishing workflows, so omission of strong warnings and confirmation requirements materially raises the chance of accidental or unauthorized posting/modification of user content.
The documentation explicitly promotes bypassing normal browser interaction by directly invoking framework event handlers such as React/Vue click callbacks. In a browser automation skill, this can trigger privileged site actions like publish, submit, or delete in ways that evade normal UI gating, confirmation flows, or trusted-event checks, increasing the risk of unintended or unauthorized state-changing actions on third-party sites.
This documentation explicitly teaches anti-detection techniques to evade site controls, including using native CDP events because they produce isTrusted=true interactions and preserving xsec_token values needed for access. That goes beyond ordinary automation guidance and materially enables bypass of platform restrictions, anti-bot defenses, and likely terms-of-service enforcement.
The file documents workflows for scraping, extracting comments, and scaling collection patterns without any warning about consent, privacy, authorization, or impact on target sites. In context, the absence of safety constraints makes the anti-detection material more operationally dangerous because it normalizes covert collection from real platforms.
The generic section recommends choosing CDP native events and human-like typing specifically to bypass anti-bot detection, including cases where sites inspect isTrusted. That is generalizable evasion guidance that can be applied broadly across protected sites, increasing abuse potential beyond the named example.
The script exposes Runtime.evaluate over CDP, which can execute arbitrary JavaScript inside the selected tab and therefore inspect page contents, session state, or modify the page. Although the function names say 'Execute JS', there is no explicit safety warning or confirmation that this operation can affect user data or page state in the user's daily browser.
The screenshot path captures the current page and saves the resulting image to a local file, which may include sensitive on-screen information. While the code prints the saved filename afterward, it does not warn users beforehand that page contents will be persisted to disk.
The manifest describes a skill for controlling Brave via CDP for browsing, extraction, screenshots, and JavaScript execution. In addition to CDP control, this file invokes separate local Python processes via subprocess.run to handle interaction, page-state, and framework-click features, which is a broader host-level execution capability not justified by the stated browser-focused purpose.
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
if args.text:
cmd += ["--text", args.text]
cmd += ["--index", str(args.index)]
subprocess.run(cmd)
elif args.command in ("elements", "pagination", "snapshot", "page-status", "count"):
# Delegate to page_state.py
import subprocess, os
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
if args.text:
cmd += ["--text", args.text]
cmd += ["--index", str(args.index)]
subprocess.run(cmd)
elif args.command in ("elements", "pagination", "snapshot", "page-status", "count"):
# Delegate to page_state.py
import subprocess, os
No suspicious patterns detected.