Back to skill

Security audit

Remote Chrome CDP

Security checks for vulnerabilities and agentic risk

Overview

This skill does what it says, but it asks users to expose powerful Chrome remote-control access in ways that can affect real logged-in browser accounts without enough warning or isolation guidance.

Install only if you understand that CDP access is effectively full control over the attached Chrome session. Use a dedicated disposable browser profile with no personal sync, saved passwords, payment data, or important accounts; bind and tunnel only to localhost; stop the Chrome and SSH tunnel when done; and install Python dependencies in a virtual environment with pinned versions where possible.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:16
Finding

Permissive Chrome DevTools Protocol Configuration Exposes Authenticated Browser Sessions

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 16–33
Vulnerability Type: Unsafe browser debugging configuration
Risk Level: High

Vulnerable Code

bash
### Linux
google-chrome \
  --remote-debugging-port=9222 \
  --remote-allow-origins=* \
  --user-data-dir=~/.config/chrome-cdp

### macOS
/Applications/Google\ Chrome.app/Contents/MacOS/Google\ Chrome \
  --remote-debugging-port=9222 \
  --remote-allow-origins=* \
  --user-data-dir="$HOME/.config/chrome-cdp"
text
Note: Use a dedicated `--user-data-dir` (e.g. `~/.config/chrome-cdp`) — Chrome 126+ blocks CDP on the default profile by design. Log in with your Google account once to enable sync.

Note: On macOS, omit `--user-data-dir` only if you don't need sync — it gives you your real profile with extensions and custom shortcuts.

The permissive --remote-allow-origins=* configuration is repeated at SKILL.md:77-78, while SKILL.md:172-176 reiterates that the wildcard should be used and suggests exposing the real profile.

Technical Analysis

Chrome DevTools Protocol provides extensive control over the browser, including navigating tabs, executing JavaScript, reading page content, inspecting network traffic, and interacting with authenticated applications. Allowing every WebSocket origin removes an important origin restriction from the CDP endpoint.

The exposure is made more severe by instructions to sign into a Google account in the debugging profile and by the alternative recommendation to expose the user's real Chrome profile. A CDP endpoint attached to either profile may provide access to authenticated pages, browser state, application tokens available to page contexts, and sensitive information displayed or transmitted by open tabs.

Although the documented Chrome command does not explicitly bind CDP to a non-loopback interface, local malicious processes and potentially hostile browser origins able to reach the ...[truncated 1791 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove --remote-allow-origins=* and configure the narrowest possible trusted origin.
  • Explicitly bind the debugging endpoint to loopback using an appropriate Chrome debugging address option.
  • Never expose the CDP port directly to a LAN, public interface, container bridge, or untrusted proxy.
  • Use a dedicated, disposable browser profile containing no personal accounts, saved credentials, payment data, or synchronized browser state.
  • Remove the recommendation to sign into a Google account or use the real Chrome profile.
  • Protect remote access through authenticated SSH forwarding and restrictive SSH authorization policies.
  • Prefer local-only forwarding, such as -L 127.0.0.1:9223:127.0.0.1:9222, and prohibit remote gateway binding.
  • Run the browser under a dedicated low-privilege operating-system account when handling untrusted sites.
  • Add an explicit warning that CDP access is effectively equivalent to control of the attached browser session.
  • Verify at startup that the debugging port is not reachable from non-loopback interfaces.

T08 · Insecure Dependencies

Warning
Location
SKILL.md:87
Finding

Unpinned Third-Party Python Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 87–90
Vulnerability Type: Unpinned external dependency
Risk Level: Medium

Vulnerable Code

bash
Install dependency (once):
pip install websocket-client

Technical Analysis

The installation command retrieves the current release of websocket-client without pinning a reviewed version or validating package hashes. It also does not require a virtual environment, lock file, or explicitly trusted package index.

Consequently, the effective dependency installed by this Skill can change after the Skill itself has been reviewed. A compromised upstream release, compromised package repository, maliciously configured package index, or unexpected future package behavior could introduce unreviewed code into the environment.

This finding does not establish that websocket-client is malicious. The issue is that the documented installation process lacks controls that provide dependency integrity, reproducibility, and isolation.

Attack Path

  1. A user runs pip install websocket-client as instructed.
  2. pip resolves the package from the user's configured package indexes and selects the latest compatible release.
  3. An attacker compromises an accepted package source, publishes a compromised future release, or controls a package index configured in the environment.
  4. The attacker's package content is downloaded and installed without version or hash verification.
  5. Malicious code may execute during installation or when the supplied Python example imports and uses the package.

Impact Assessment

Exploitation would execute code with the privileges of the user running pip or the Python automation script. Depending on those privileges and the environment, impact may include:

  • Reading or modifying files available to the user.
  • Accessing environment variables and locally stored credentials.
  • Altering Python packages or application beh ...[truncated 380 chars]
Remediation
View remediation

Remediation Suggestions

  • Pin the dependency to a specifically reviewed version, for example through a version-locked requirements file.
  • Record and enforce cryptographic hashes with pip install --require-hashes.
  • Install dependencies inside a dedicated virtual environment rather than the system Python environment.
  • Use an explicitly approved HTTPS package index and disable unintended supplemental indexes.
  • Maintain a lock file and review dependency updates before changing pinned versions.
  • Scan dependencies for known vulnerabilities as part of routine maintenance.
  • Instruct users not to run the installation command with sudo or another elevated account.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill explicitly suggests using a real or synced Chrome profile with CDP, which exposes cookies, extensions, saved sessions, and account data to any process or operator that can drive DevTools. In this context, CDP is not read-only automation: it can navigate authenticated pages, execute JavaScript, and exfiltrate sensitive data, so omitting a strong warning materially increases risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The SSH tunnel guidance makes remote CDP access easy but does not clearly state that CDP provides near-total browser compromise, including control of authenticated sessions, page content, downloads, and script execution. While SSH limits exposure compared with an open port, the remote-control context makes the omission more dangerous because users may treat the tunnel as inherently safe and overlook the sensitivity of the browser session behind it.

Content

No source excerpt is available for this finding.

Internal Network Request

Medium
Category
Server-Side Request Forgery
Confidence
70% confidence
Finding

Code issues a request to a loopback, link-local, or private-range host. This can reach internal services not meant to be exposed and is a common SSRF pivot.

Content

Scanner excerpt · SKILL.md (reported line 107)May include surrounding context.

md
return None

# Open a new tab
req = urllib.request.Request(f"http://localhost:{PORT}/json/new", method="PUT")
tab = json.loads(urllib.request.urlopen(req).read())

# Connect via WebSocket — origin header is required

Static analysis

No suspicious patterns detected.