Back to skill

Security audit

Agent Browser Clawdbot.Bak 2026 01 28T18:01:09+10:30

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent browser automation helper, but it recommends persisting reusable browser authentication state and installing an unpinned global CLI without enough safety guidance.

Review before installing. Use a least-privilege test account where possible, keep saved auth state files out of source control and logs, store them only in access-controlled locations, delete them after use, and pin or verify the agent-browser package and downloaded browser/runtime components before running global installs.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:197
Finding

Unpinned Global Installation of a Third-Party npm Package

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 197-200
Vulnerability Type: Unpinned third-party dependency and unsafe global installation
Risk Level: Medium

bash
npm install -g agent-browser
agent-browser install                     # Download Chromium
agent-browser install --with-deps         # Linux: + system deps

Technical Analysis

The installation instructions globally install agent-browser without specifying an exact package version or verifying an integrity digest. Consequently, npm resolves the package release available at installation time rather than a release that was reviewed with this skill.

npm installation can execute package lifecycle scripts. After installation, the documented CLI commands also download Chromium and may install operating-system dependencies. Those remotely obtained components and their installation behavior are not present in the audited artifact and therefore cannot be verified by this static review.

The combination of an unpinned dependency, global installation, lifecycle-script execution, and subsequent component downloads creates a software supply-chain exposure. Exploitation would require compromise or malicious control of the npm package, its publication channel, or another relevant distribution endpoint.

Attack Path

  1. An attacker compromises the agent-browser package publication channel, maintainer credentials, or an associated component distribution endpoint.
  2. The attacker publishes a malicious or modified release under the package name or replaces a downloaded installation artifact.
  3. A user follows the skill documentation and runs npm install -g agent-browser.
  4. npm resolves the attacker-controlled current release because no exact version or integrity value is specified.
  5. Malicious lifecycle scripts or installed package code execute with the privileges of the user running npm.
  6. The user subsequently runs `agent-browser inst ...[truncated 834 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin agent-browser to an exact, reviewed version instead of installing the latest available release.
  2. Use a project-local dependency with a committed lockfile rather than a global installation where feasible.
  3. Verify package integrity through a trusted registry, recorded cryptographic digest, provenance attestations, and package signatures where supported.
  4. Audit npm lifecycle scripts before installation and disable them with --ignore-scripts when they are not required.
  5. Pin and verify Chromium downloads and other external installation artifacts using documented versions and checksums.
  6. Separate browser installation from operating-system dependency installation, and clearly document when elevated privileges may be requested.
  7. Run installation in a least-privileged, isolated environment and avoid using an administrator or root account.
  8. Document the expected official package publisher and distribution endpoints so users can detect package substitution or registry misconfiguration.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill explicitly documents saving and loading browser state, cookies, and local storage, which commonly contain session tokens and other authentication material, but provides no warning about their sensitivity or safe handling. In an agent-oriented automation context, this increases the chance that users or downstream agents persist reusable auth artifacts to insecure locations, accidentally exfiltrate them, or reuse them across contexts in unsafe ways.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.