Back to skill

Security audit

Browser Agent Bridge CLI

Security checks across malware telemetry and agentic risk

Overview

This skill is openly designed to control a live Chrome tab, but it grants broad browser authority with limited scoping and cleanup guidance.

Install only if you intentionally want an agent to operate your real browser. Prefer a separate Chrome profile or test account, review the external CLI and extension source, pin trusted versions where possible, generate fresh tokens per session, keep the operator token private, confirm any sensitive action before it is taken, and stop the background bridge and disconnect the extension when finished.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill enables direct control of a live Chrome tab, including navigation, clicking, typing, and HTML extraction, but the introductory usage guidance does not prominently warn that these actions can alter the user's active session and expose page data. In this context, omission of that warning increases the risk of unsafe use, unintended state changes, and disclosure of sensitive content from authenticated browser pages.

Missing User Warnings

Medium
Confidence
86% confidence
Finding
The setup flow instructs the agent to share the bridge token with the user for extension configuration, but the extension setup section lacks a clear warning that this token is a secret granting browser-bridge access. In a tool that can remotely observe and control a live browser tab, unclear handling guidance for authentication tokens raises the chance of accidental disclosure, reuse, or misuse by other local processes or users.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.