Back to skill

Security audit

Browser Capture

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its screenshot and image-capture purpose, but it includes guidance that can bypass website protections and writes downloaded remote images to local files without much scoping.

Install only if you are comfortable with a capture helper that may download remote image URLs directly to local files. Do not use its proxy advice to bypass Cloudflare, bot checks, paywalls, login gates, or other site protections, and choose safe output paths before running download or copy commands.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The documentation recommends using a proxy service to get around Cloudflare protections, which is a circumvention technique unrelated to the core purpose of ordinary screenshot/image capture. Encouraging bypass of site access controls increases the risk of unauthorized access, policy evasion, and misuse against protected services.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill is presented as a browser-based screenshot/image capture helper, but it instructs users to use curl for direct network retrieval and local file writes outside the declared browser tooling. This broadens the skill's operational scope, can enable downloading arbitrary remote content to the local filesystem, and bypasses any guardrails or visibility associated with the browser-specific tools.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The complete example repeats the use of curl to directly download a remote image, normalizing behavior outside the stated browser-capture capability. Repetition in an end-to-end workflow makes misuse more likely and further encourages arbitrary network access and local file creation beyond the intended tool boundary.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill instructs saving downloaded content and copying files into the workspace without warning about local file writes, overwrites, or storage hygiene. While the commands are simple, they can still lead to accidental clobbering of files or persistence of untrusted remote content on the local system.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.