T09 · Insecure Skill Coding Practices
- Location
REFERENCE.md:454- Finding
Persistent Browser Profile Retains Authentication Data Across Sessions
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This browser automation skill is purpose-aligned but needs Review because it grants broad web, session, download, and remote-browser authority without enough user-directed controls.
Review this carefully before installing. Use it only in a workspace where broad browser automation is acceptable, avoid logging into sensitive accounts unless you isolate or clear the browser profile, do not rely on it for private/internal sites without explicit controls, and treat downloaded files as untrusted. Also verify the actual npm package/source before running npm install or npm link, because the reviewed artifact did not include the CLI implementation.
REFERENCE.md:454Persistent Browser Profile Retains Authentication Data Across Sessions
REFERENCE.md:375Unrestricted Internal Network Access Combined with Automatic Unvalidated Downloads
The login example instructs entering credentials and capturing a screenshot of an authenticated dashboard, but does not warn about credential handling, session sensitivity, or exposure of private account data in screenshots. In the context of a browser automation skill, this is especially dangerous because it can access live accounts and preserve or reveal secrets, personal data, and privileged business information.
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
### First: Environment Selection (Local vs Remote)
The skill automatically selects between local and remote browser environments:
- **If Browserbase API keys exist** (BROWSERBASE_API_KEY and BROWSERBASE_PROJECT_ID in .env file): Uses remote Browserbase environment
- **If no Browserbase API keys**: Falls back to local Chrome browser
- **No user prompting**: The selection happens automatically based on available configuration
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
### First: Environment Selection (Local vs Remote)
The skill automatically selects between local and remote browser environments:
- **If Browserbase API keys exist** (BROWSERBASE_API_KEY and BROWSERBASE_PROJECT_ID in .env file): Uses remote Browserbase environment
- **If no Browserbase API keys**: Falls back to local Chrome browser
- **No user prompting**: The selection happens automatically based on available configuration
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
### First: Environment Selection (Local vs Remote)
The skill automatically selects between local and remote browser environments:
- **If Browserbase API keys exist** (BROWSERBASE_API_KEY and BROWSERBASE_PROJECT_ID in .env file): Uses remote Browserbase environment
- **If no Browserbase API keys**: Falls back to local Chrome browser
- **No user prompting**: The selection happens automatically based on available configuration
The contact-form example automates filling and submitting external data without warning that this sends information to a third-party site and may trigger real-world effects. That normalizes external side effects and could lead users or agents to submit personal, confidential, or unintended data without adequate review.
The note that Chrome's user profile may preserve session cookies between runs introduces persistent authenticated state beyond a simple stateless browsing tool. Session reuse can expose prior users' authenticated contexts, enable cross-task data leakage, and cause actions to be performed under unintended accounts.
The examples document a file download workflow that writes content to disk automatically, but the skill description only frames the capability as browser interaction and data extraction. Underspecified download behavior can lead users or downstream agents to fetch and persist untrusted files without explicit consent, creating risk of unsafe file handling or unintended storage of malicious content.
The download example states that files are automatically written to ./agent/downloads/ but does not warn that this creates a persistent external side effect on local storage. Users may unintentionally save untrusted or sensitive files, which increases risk of malware staging, data retention issues, or confusion about where content is stored.
The file documents a persistent Chrome profile directory and later notes that saved passwords and cookies persist between sessions, but this risk is not surfaced prominently in command behavior where browsing actions occur. In this skill context, persistent session state makes browser automation more dangerous because future tasks may inherit authenticated sessions, leak cross-task data, or perform actions with retained credentials unintentionally.
The reference explicitly documents that downloads are automatically saved to disk with no file type restrictions, but the command behavior sections do not prominently warn users before use. In an agent-driven browser tool, this can cause unreviewed files to be written locally from untrusted sites, increasing the risk of malware staging, accidental handling of sensitive files, or disk persistence of unsafe content.
The skill explicitly states it will automatically switch to a remote Browserbase environment whenever API keys are present, with no user prompting or warning. That can silently send URLs, page contents, form inputs, cookies, screenshots, and other browsing artifacts to a third-party service, creating a real data-exposure and privacy risk even if the feature is intended for convenience.
No suspicious patterns detected.