Back to skill

Security audit

Webperf Resources

Security checks for vulnerabilities and agentic risk

Overview

This skill is a web performance helper, but it overstates its browser script capability and encourages automatic follow-up script execution without clear user control.

Review before installing. Only use this skill on pages you are comfortable inspecting through DevTools, confirm each script run explicitly, and do not rely on its current network metrics without fixing the included snippet to return the claimed connection data.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (7)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The description substantially overstates the functionality. While the code touches the Network Information API, it does not analyze network quality, read and act on connection properties, or implement any adaptive loading behavior. Its actual behavior is limited to feature detection and attaching a no-op listener, which is materially different from the declared purpose.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The activation guidance is broad enough that the skill may trigger for routine performance questions, causing unnecessary execution of browser-evaluation snippets in a live page context. Overbroad invocation criteria increase the chance of running active inspection code without sufficiently specific user intent or scope confirmation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill directly instructs use of mcp__chrome-devtools__evaluate_script, which runs active JavaScript in the inspected page context, but it does not warn about side effects, privacy exposure, or the need for user authorization. In a browser-analysis environment, silent execution guidance is risky because even diagnostic scripts can read page state, trigger handlers, or affect application behavior.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The workflow boundaries between this skill and related performance skills are unclear, which can lead to unnecessary chaining across multiple tools and scripts. In an agent setting, ambiguous routing raises the risk of excessive code execution, data collection, or scope creep beyond what the user intended.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
90% confidence
Finding

The skill promotes autonomous decision making by telling the agent to 'automatically run' follow-up snippets based on observed conditions. In a security-sensitive tool environment, this reduces human oversight and can cause cascading tool use, broader inspection, and unreviewed actions in the target browser context.

Content

Scanner excerpt · SKILL.md (reported line 68)May include surrounding context.

md
## Decision Tree

Use this decision tree to automatically run follow-up snippets based on results:

### After Network-Bandwidth-Connection-Quality.js

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The phrase 'automatically run follow-up snippets' is unsafe in a skill that operates through Chrome DevTools script evaluation, because it encourages autonomous execution based on intermediate results rather than explicit user consent. This can expand the number of active scripts executed in the inspected page context and make agent behavior less predictable and less controllable.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The quoted trigger phrase 'optimize for mobile' or similar wording is generic and likely to match many benign optimization requests. This primarily creates an overreach risk where the agent may pivot into live script execution when a high-level advisory answer would have been sufficient.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.