Back to skill

Security audit

Skyvern

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent Skyvern connector, but it gives agents broad authority to start browser automation through a connected account with weaker confirmation guidance than that authority needs.

Review before installing if your Skyvern account can automate logged-in or sensitive websites. Use it only when you explicitly want the agent to operate Skyvern, and require confirmation before starting or canceling any run, including run_task payloads.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The skill description says to use this skill for ANY Skyvern request and instead of calling the API directly, which is broad enough to trigger on casual mentions of Skyvern rather than clear user intent to invoke automation. That can cause unintended tool use and, in this skill, may lead to external actions such as listing runs, fetching run data, or initiating/canceling runs when the user only wanted discussion or analysis.

Static analysis

No suspicious patterns detected.