Back to skill

Security audit

browseanything ai browser agent

Security checks for vulnerabilities and agentic risk

Overview

This hosted browser automation skill is coherent, but it needs Review because it can act in logged-in sessions, submit forms or transactions, and send sensitive browsing data to a remote service without enough confirmation and privacy guardrails.

Install only if you trust the BrowseAnything service and intend to delegate real browser activity to it. Prefer project-scoped installation, use limited and revocable API keys, keep custom endpoints HTTPS-only, avoid passing 2FA codes or secrets as command-line arguments, and require explicit user review before logins, form submissions, purchases, bookings, or private data exports.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/submit_input.py:18
Finding

Sensitive Human Input and 2FA Codes Exposed Through Command-Line Arguments

Content
View full analysis
"the user's answer" ``` ``` `EXAMPLES.md:87-98`: ```markdown If you can't supply something the task will need (a 2FA code, a clarification), the task will pause and BrowseAnything will return `status: requires_input` with a `human_input_request` question. Provide it via `submit_input.py`. Example: ```bash ID=$(python3 scripts/create_task.py "Log into my Coinbase and return the BTC balance.") # ... time passes ... python3 scripts/get_task.py "$ID" --field status # -> requires_input python3 scripts/get_task.py "$ID" --field human_input_request # Ask the actual user, not the model: python3 scripts/submit_input.py "$ID" "987654" # 2FA code python3 scripts/get_task.py "$ID" ``` ``` `scripts/submit_input.py:18-22`: ```python p.add_argument("task_id") p.add_argument("input", help="Answer to send. Use '-' to read from stdin.") args = p.parse_args() answer = sys.stdin.read().strip() if args.input == "-" else args.input ``` ### Technical Analysis The script accepts sensitive human responses directly as a positional command-line argument. The documentation explicitly demonstrates this mechanism with a Coinbase 2FA code. Command-line secrets can be exposed through: - Shell history files and history synchronization services. - Process inspection utilities while the command is running. - Endpoint monitoring, terminal recording, audit logging, ...[truncated 1969 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/_client.py:43
Finding

Configurable API Endpoint Permits Plaintext Transmission of API Credentials and Task Data

Content
View full analysis
str: return os.environ.get("BROWSEANYTHING_API_URL", DEFAULT_BASE_URL).rstrip("/") def request( method: str, path: str, body: dict | None = None, raw: bool = False, timeout: int = 60, ) -> Any: """Perform a single HTTP request against the API. Returns the parsed JSON body unless raw=True, in which case the raw bytes are returned (used for screenshots). """ url = f"{_base_url()}{path}" data = None headers = { "Authorization": f"Bearer {_api_key()}", "Accept": "application/json", "User-Agent": "browse-anything-skill/1.0 (+https://browseanything.io)", } if body is not None: data = json.dumps(body).encode("utf-8") headers["Content-Type"] = "application/json" req = urllib.request.Request(url, data=data, headers=headers, method=method) ``` The endpoint is documented as configurable. For example, `README.md:133-136` states: ```markdown set: ```bash export BROWSEANYTHING_API_URL=https://your-host ``` ``` ### Technical Analysis The default endpoint uses HTTPS, but `_base_url()` accepts an arbitrary environment-variable value without parsing or validating its scheme. Consequently, values such as the following are accepted: ```bash export BROWSEANYTHING_API_URL=http://example.internal ``` Every request then includes the long-lived BrowseAnything API key in the `Authorization` header. Task-creation and input-submission requests may additionally include: - Natural-language prompts. - Metadata. - Authenticated workflow details. - Human responses, potentially including 2FA codes. - Task identifiers and results. When an HTTP endpoint is used across ...[truncated 2024 chars]
Remediation
View remediation
str: value = os.environ.get( "BROWSEANYTHING_API_URL", DEFAULT_BASE_URL, ).rstrip("/") parsed = urllib.parse.urlparse(value) if parsed.scheme != "https": raise RuntimeError( "BROWSEANYTHING_API_URL must use HTTPS." ) if not parsed.hostname or parsed.username or parsed.password: raise RuntimeError("Invalid BROWSEANYTHING_API_URL.") return value ``` 2. If plaintext HTTP is required for local development, restrict it to loopback hosts such as `127.0.0.1`, `::1`, and `localhost`. 3. Require an explicit development-only opt-in before allowing loopback HTTP, such as `BROWSEANYTHING_ALLOW_INSECURE_LOCALHOST=1`. 4. Never permit HTTP for remote or non-loopback destinations when attaching the authorization header. 5. Reject URLs containing embedded usernames or passwords and schemes other than HTTPS. 6. Document that the API endpoint receives the bearer key, prompts, metadata, and submitted human input. 7. Use narrowly scoped, revocable API keys for self-hosted deployments and rotate any key that may have been sent over an insecure connection. 8. Add automated tests confirming that remote HTTP URLs are rejected and the default HTTPS endpoint remains accepted. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (24)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The README promotes a hosted browsing platform that can 'log into apps', 'extract data behind authentication', and 'complete checkout flows' but does not prominently warn that user prompts, browsing actions, page contents, screenshots, and potentially sensitive authenticated data may be transmitted to a third-party hosted service. This omission is especially dangerous because users may unknowingly expose credentials, personal data, or confidential business information to an external processor.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · REFERENCE.md (reported line 91)May include surrounding context.

md
Body: `{ "input": "..." }`. Resumes a `requires_input` task. Returns
`{ "success": true, "message": "Input received, task execution resumed" }`.

### `DELETE /api/v1/tasks/{id}`

Cancels a queued or running task. Idempotent.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description centers on browser automation for interacting with websites on a user's behalf. The actual code does not launch or control a browser, navigate web pages, scrape content, fill forms, or perform any web task directly. Instead, it is a narrow administrative script for cancelling an existing task through an API endpoint. That is a materially different primary purpose and capability from the declared browsing/automation behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description promises an active browser automation capability for interacting with websites in real time. However, the code shown only implements a task-listing utility that fetches recent tasks from an API and prints their status, step count, and prompt. This is a materially different primary purpose: administrative inspection of previously created tasks, not autonomous browser operation. While it may be related to the same platform, the behavior in this code chunk does not match the declared end-user capability.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description presents the skill as an autonomous browser automation tool for interacting with arbitrary websites. However, the supplied code chunk only checks the BrowseAnything service backend status via /api/v1/status and prints the result. This is a materially different primary purpose: operational monitoring of the hosted platform rather than browsing or acting on web pages. There is no evidence in this code of controlling Chromium, visiting websites, scraping content, logging into apps, or completing user web tasks. Therefore the description does not accurately represent this code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description presents a full-featured live web automation/browser skill. The supplied code does not perform any browser automation or website interaction at all. Instead, it is a narrow helper script for submitting user input to a task via an API endpoint. This is a materially different primary purpose and accesses a different kind of resource than declared, so it is a clear description-behavior mismatch.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger guidance is extremely broad, encouraging activation for generic requests like 'browse', 'log in', 'buy', 'book', and 'fill out a form'. In an agentic environment, this can route ordinary user queries into a high-impact autonomous web tool capable of authenticated actions and transactions, increasing the chance of unintended account access, purchases, data extraction, or policy bypass.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill advertises capabilities like logging into apps, filling forms, booking, buying, and extracting authenticated data without a prominent safety warning or consent model. Because these are high-impact state-changing actions involving credentials, financial transactions, and private data, missing warnings materially increase the risk of unauthorized or accidental actions by downstream agents or users.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 155)May include surrounding context.

md
- `REFERENCE.md` — full API surface, request/response shapes, status enum

Lp1

High
Category
MCP Least Privilege
Confidence
75% confidence
Finding

The skill uses 'env' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.

Content

No source excerpt is available for this finding.

Lp1

High
Category
MCP Least Privilege
Confidence
75% confidence
Finding

The skill uses 'network' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The example explicitly instructs the agent to fill and submit a live form containing personal data, then confirm success, without any guidance to require explicit user confirmation before the irreversible action. In a browser automation skill designed to act on real websites, this normalizes state-changing behavior and increases the risk of unintended submissions, privacy exposure, or misuse against third-party services.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The authenticated workflow example instructs extraction of account-specific LinkedIn notifications from an already logged-in session, but omits any warning that the data is private and should only be accessed with the account holder's authorization. Because this skill is specifically for live browser control with saved sessions, the example could facilitate unauthorized access to sensitive personal information if misused.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The Notion example directs the agent to open a logged-in workspace database and export recent entries, which may contain confidential business or personal information, yet provides no warning about sensitivity, least-privilege handling, or authorization. In the context of a tool marketed for scraping behind authentication, this materially increases the risk of data exfiltration from private workspaces.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 54)May include surrounding context.

bash
# project-scoped (recommended for shared repos)
mkdir -p .claude/skills
cp -r skills/browse-anything .claude/skills/

# or user-scoped (every project sees it)

Session Persistence

Medium
Category
Rogue Agent
Confidence
74% confidence
Finding

The README explicitly recommends a user-scoped installation where 'every project sees it', which increases persistence and blast radius for a highly privileged skill that can browse, log in, scrape, and perform actions on websites. In the context of an auto-discovered agent skill, global persistence makes unintended activation or misuse across unrelated repositories and tasks more likely.

Content

Scanner excerpt · README.md (reported line 54)May include surrounding context.

bash
# project-scoped (recommended for shared repos)
mkdir -p .claude/skills
cp -r skills/browse-anything .claude/skills/

# or user-scoped (every project sees it)

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 58)May include surrounding context.

cp -r skills/browse-anything .claude/skills/

or user-scoped (every project sees it)

mkdir -p ~/.claude/skills cp -r skills/browse-anything ~/.claude/skills/

text

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The README states the skill is auto-triggered by broad phrases like 'browse', 'scrape', 'log into', and 'fill form', which are common requests and can cause the skill to activate in many contexts. For a capability that can control a real browser and interact with authenticated sites, overly broad triggering increases the chance of unintended invocation, data disclosure, or risky actions being sent to the external service.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 91)May include surrounding context.

Codex CLI

bash
mkdir -p .codex/skills
cp -r skills/browse-anything .codex/skills/

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 98)May include surrounding context.

Gemini CLI

bash
mkdir -p .gemini/skills
cp -r skills/browse-anything .gemini/skills/

Rp1

Medium
Category
MCP Rug Pull
Confidence
82% confidence
Finding

The README instructs users to run npx skilltap install ... without pinning a package version or integrity, which can fetch whatever version is current at execution time. That creates a supply-chain risk: a compromised or maliciously updated package could execute arbitrary code during install on the user's machine.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The reference explicitly shows authentication values in the live-key format (ba_live_...) and does so without any warning that these are sensitive secrets. In a skill designed to drive web tasks, authenticate to services, and handle user accounts, normalizing live-token patterns increases the chance that developers or users will paste real credentials into logs, docs, prompts, or screenshots, leading to credential disclosure and unauthorized API use.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The phrase 'whenever the task requires the live web' is ambiguous and can cause overuse of a powerful automation skill where simpler, safer tools or non-actionable responses would suffice. Ambiguous routing criteria increase the likelihood that the agent performs unnecessary external interactions, exposing sessions, data, and user accounts to avoidable risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

This code sends the provided answer to a remote API endpoint, which is a network operation transmitting user-supplied data. While the script name and purpose imply submission, there is no explicit warning, log message, or comment near the operation telling the user that their input will be sent to a server.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.