Back to skill

Security audit

Agent Browser

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent browser automation helper, but it normalizes reusable login state, credential handling, recordings, and proxy credentials without enough containment guidance.

Review this skill before installing if you will use it on logged-in accounts or production sites. Use test accounts where possible, avoid saving auth state unless necessary, store state files in a private location with restrictive permissions, delete them after use, avoid recording login or private data, and keep proxy credentials out of shell history and logs.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
templates/authenticated-session.sh:16
Finding

Authentication State Is Stored Without Enforced File Permissions

Content
View full analysis
Remediation
View remediation
/dev/null || true rm -f -- "$STATE_FILE" } trap cleanup EXIT ``` Persistent reuse should be explicitly requested rather than enabled by default. 6. Add comprehensive ignore rules matching all documented names: ```gitignore auth-state.json *-state.json *.auth-state.json ``` Ignore rules should supplement, not replace, filesystem permissions. 7. Set short expiration periods for reusable sessions, revoke saved sessions after CI runs, and avoid persisting sessions created after MFA unless strictly necessary. 8. Update all examples in `SKILL.md`, `references/authentication.md`, and `references/session-management.md` to demonstrate private storage and restrictive permissions. ]]>

T09 · Insecure Skill Coding Practices

Note
Location
references/proxy-support.md:24
Finding

Proxy Credentials Are Embedded in Environment Variable URLs

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (17)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/authentication.md (reported line 179)May include surrounding context.

  1. Clean up after automation

    bash
    agent-browser cookies clear
    rm -f ./auth-state.json
    
  2. Use short-lived sessions for CI/CD

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/session-management.md (reported line 173)May include surrounding context.

echo "*.auth-state.json" >> .gitignore

Delete after use

rm /tmp/auth-state.json

text

### 4. Timeout Long Sessions

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The example records a login workflow while filling a password field, which would expose the credential or sensitive login flow details in the saved video unless masking is enforced. This is especially dangerous in a browser automation context because recordings are often uploaded as CI artifacts, shared for debugging, or retained on disk where unintended viewers may access them.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill description is broad enough to match many generic web-browsing, form-filling, and information-extraction requests, which increases the chance the agent invokes this powerful skill in contexts where a less privileged approach would suffice. Because the tool can navigate arbitrary URLs, interact with authenticated sessions, and access local/file/data schemes, overbroad activation expands the attack surface for prompt-injection, data exfiltration, and unintended actions.

Content

No source excerpt is available for this finding.

Context Window Stuffing

Medium
Category
Memory Poisoning
Confidence
85% confidence
Finding

Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.

Content

Scanner excerpt · SKILL.md (reported line 15)May include surrounding context.

agent-browser open # Navigate to page agent-browser snapshot -i # Get interactive elements with refs agent-browser click @e1 # Click element by ref agent-browser fill @e2 "text" # Fill input by ref agent-browser close # Close browser

text

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documentation promotes persisting cookies/storage and setting credentials without prominently warning that these artifacts may contain session tokens, account data, or secrets that can be reused across tasks. In an agent setting, retained browser state materially raises the risk of cross-task data leakage, unauthorized account actions, and compromise if saved state files are exposed or reused too broadly.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
94% confidence
Finding

The skill explicitly instructs saving and later loading authenticated browser state, which can preserve reusable session cookies and other authentication artifacts. If these files are retained insecurely, shared across users/tasks, or loaded without strict scoping, an attacker or unintended workflow could hijack an authenticated session and access protected resources without re-authentication.

Content

Scanner excerpt · SKILL.md (reported line 283)May include surrounding context.

agent-browser wait --url "**/dashboard" agent-browser state save auth.json

Later sessions: load saved state

agent-browser state load auth.json agent-browser open https://app.example.com/dashboard

text

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The example encourages saving reusable browser authentication state to a local file immediately after login, and the warning that such files contain active session tokens appears only much later in the document. Readers may copy this pattern without understanding that the file is equivalent to bearer credentials and can enable account takeover if exposed through source control, shared workspaces, logs, or artifacts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The OAuth/SSO flow saves post-login state after a third-party authentication sequence without a nearby warning that the resulting file may contain active cookies, tokens, and federated session artifacts. Because OAuth sessions often grant access across important accounts, an exposed saved state file can let an attacker replay an authenticated session without knowing the user's password.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation explicitly demonstrates embedding proxy usernames and passwords in environment variable URLs without warning that such secrets may be exposed through shell history, process/environment inspection, CI logs, crash reports, or shared session environments. In a browser automation skill, proxy credentials may grant access to paid proxy networks or sensitive corporate egress paths, so normalizing this pattern increases the risk of credential leakage and misuse.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The rotating-proxy scraping example encourages routing web requests and extracted page data through third-party proxies to avoid rate limiting, but provides no warning that traffic and collected content may transit untrusted infrastructure or violate site terms, privacy requirements, or organizational policy. In this skill context, the feature directly automates browsing and extraction at scale, which makes omission of these cautions more operationally dangerous than a generic networking example.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The save/load examples demonstrate persisting browser session state containing cookies and storage data before clearly warning that these files can contain active authentication tokens and other sensitive material. In a browser automation skill, this is operationally dangerous because users may store state files in insecure locations, reuse them across contexts, or expose them through logs, temp directories, or source control.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
88% confidence
Finding

Loading saved session state restores authentication context, which can bypass normal login flows if the state file is stolen, copied, or reused across systems. In this skill's context, that is materially risky because the tool is specifically designed to automate browser actions, making persisted sessions directly actionable for account access.

Content

Scanner excerpt · references/session-management.md (reported line 43)May include surrounding context.

Load Session State

bash
# Restore saved state
agent-browser state load /path/to/auth-state.json

# Continue with authenticated session

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The authenticated session reuse script shows saving credentials-derived authenticated state to /tmp/auth-state.json and reloading it later without an immediate security warning. This can normalize insecure handling of secrets and sessions, especially because /tmp is commonly shared, ephemeral, and easier to access or leak in multi-user or CI environments.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation promotes recording browser sessions and taking screenshots but does not warn that these artifacts can capture sensitive information such as credentials, personal data, session tokens shown in pages, or internal application content. In a browser automation skill, this omission is security-relevant because users are likely to apply the examples to real environments and may store or share recordings insecurely.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This markdown file demonstrates filling an email and password field and submitting a login form, but it does not include any user warning about entering real credentials or the sensitivity of authentication data. For markdown files, SQP-2 applies when the description omits warnings about behaviors that could affect user data or privacy.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This code performs a file deletion with rm -f "$STATE_FILE", which is a destructive operation. Although the script prints that the session expired, it does not explicitly warn the user that the saved state file will be removed or ask for confirmation before deleting it.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.