Back to skill

Security audit

Win11 Visible Browser

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed helper for controlling a visible Windows browser from WSL, with real privacy and account-action risks that are mostly scoped and approval-gated.

Install only if you want OpenClaw to control a visible Windows browser. Prefer the dedicated browser profile, close sensitive tabs before diagnostics, do not expose the CDP relay outside WSL/Hyper-V, and approve account, payment, form, firewall, config, or persistence changes only for a specific task with a clear rollback path.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
80% confidence
Finding
The description is broad enough to trigger on many ordinary browsing tasks, while this skill grants access to a live visible browser session with real tabs, cookies, logins, and account state. Over-broad routing increases the chance the agent invokes a high-privilege skill unnecessarily, exposing sensitive session data or enabling impactful actions in a user’s real browser context.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The script connects to a Chrome DevTools Protocol endpoint and enumerates live browser targets, then prints page titles and full URLs. In this skill context, the browser is explicitly the user's real visible session with existing tabs, cookies, and logins, so outputting that data can expose sensitive browsing activity, account paths, query parameters, and internal URLs to logs or downstream tooling without any minimization or user warning.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.