Back to skill

Security audit

Agent Browser - Stagehand

Security checks for vulnerabilities and agentic risk

Overview

This browser automation skill is purpose-aligned but needs Review because it grants broad web, session, download, and remote-browser authority without enough user-directed controls.

Review this carefully before installing. Use it only in a workspace where broad browser automation is acceptable, avoid logging into sensitive accounts unless you isolate or clear the browser profile, do not rely on it for private/internal sites without explicit controls, and treat downloaded files as untrusted. Also verify the actual npm package/source before running npm install or npm link, because the reviewed artifact did not include the CLI implementation.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
REFERENCE.md:454
Finding

Persistent Browser Profile Retains Authentication Data Across Sessions

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
REFERENCE.md:375
Finding

Unrestricted Internal Network Access Combined with Automatic Unvalidated Downloads

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The login example instructs entering credentials and capturing a screenshot of an authenticated dashboard, but does not warn about credential handling, session sensitivity, or exposure of private account data in screenshots. In the context of a browser automation skill, this is especially dangerous because it can access live accounts and preserve or reveal secrets, personal data, and privileged business information.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 14)May include surrounding context.

md
### First: Environment Selection (Local vs Remote)

The skill automatically selects between local and remote browser environments:
- **If Browserbase API keys exist** (BROWSERBASE_API_KEY and BROWSERBASE_PROJECT_ID in .env file): Uses remote Browserbase environment
- **If no Browserbase API keys**: Falls back to local Chrome browser
- **No user prompting**: The selection happens automatically based on available configuration

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · setup.json (reported line 17)May include surrounding context.

json
### First: Environment Selection (Local vs Remote)

The skill automatically selects between local and remote browser environments:
- **If Browserbase API keys exist** (BROWSERBASE_API_KEY and BROWSERBASE_PROJECT_ID in .env file): Uses remote Browserbase environment
- **If no Browserbase API keys**: Falls back to local Chrome browser
- **No user prompting**: The selection happens automatically based on available configuration

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · setup.json (reported line 29)May include surrounding context.

json
### First: Environment Selection (Local vs Remote)

The skill automatically selects between local and remote browser environments:
- **If Browserbase API keys exist** (BROWSERBASE_API_KEY and BROWSERBASE_PROJECT_ID in .env file): Uses remote Browserbase environment
- **If no Browserbase API keys**: Falls back to local Chrome browser
- **No user prompting**: The selection happens automatically based on available configuration

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The contact-form example automates filling and submitting external data without warning that this sends information to a third-party site and may trigger real-world effects. That normalizes external side effects and could lead users or agents to submit personal, confidential, or unintended data without adequate review.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The note that Chrome's user profile may preserve session cookies between runs introduces persistent authenticated state beyond a simple stateless browsing tool. Session reuse can expose prior users' authenticated contexts, enable cross-task data leakage, and cause actions to be performed under unintended accounts.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The examples document a file download workflow that writes content to disk automatically, but the skill description only frames the capability as browser interaction and data extraction. Underspecified download behavior can lead users or downstream agents to fetch and persist untrusted files without explicit consent, creating risk of unsafe file handling or unintended storage of malicious content.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The download example states that files are automatically written to ./agent/downloads/ but does not warn that this creates a persistent external side effect on local storage. Users may unintentionally save untrusted or sensitive files, which increases risk of malware staging, data retention issues, or confusion about where content is stored.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The file documents a persistent Chrome profile directory and later notes that saved passwords and cookies persist between sessions, but this risk is not surfaced prominently in command behavior where browsing actions occur. In this skill context, persistent session state makes browser automation more dangerous because future tasks may inherit authenticated sessions, leak cross-task data, or perform actions with retained credentials unintentionally.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The reference explicitly documents that downloads are automatically saved to disk with no file type restrictions, but the command behavior sections do not prominently warn users before use. In an agent-driven browser tool, this can cause unreviewed files to be written locally from untrusted sites, increasing the risk of malware staging, accidental handling of sensitive files, or disk persistence of unsafe content.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly states it will automatically switch to a remote Browserbase environment whenever API keys are present, with no user prompting or warning. That can silently send URLs, page contents, form inputs, cookies, screenshots, and other browsing artifacts to a third-party service, creating a real data-exposure and privacy risk even if the feature is intended for convenience.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.