Back to skill

Security audit

Browser Automation

Security checks for vulnerabilities and agentic risk

Overview

This browser automation skill is coherent but should be reviewed because it can automatically use a remote browser, retain browser sessions, and save screenshots/downloads without clear per-task user control.

Review before installing. Use it only for sites and data you are comfortable exposing to the configured browser environment and AI provider. Prefer local-only operation for sensitive work, avoid entering real passwords through natural-language commands, clear the persistent profile when needed, and inspect or delete downloaded files and screenshots after use.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (10)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill silently switches to a remote Browserbase environment whenever credentials are present, while explicitly stating there is no user prompting. This can cause browsing content, session data, form inputs, screenshots, and extracted page data to be transmitted to a third-party service without the user's awareness or consent.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 14)May include surrounding context.

md
### First: Environment Selection (Local vs Remote)

The skill automatically selects between local and remote browser environments:
- **If Browserbase API keys exist** (BROWSERBASE_API_KEY and BROWSERBASE_PROJECT_ID in .env file): Uses remote Browserbase environment
- **If no Browserbase API keys**: Falls back to local Chrome browser
- **No user prompting**: The selection happens automatically based on available configuration

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · setup.json (reported line 17)May include surrounding context.

json
### First: Environment Selection (Local vs Remote)

The skill automatically selects between local and remote browser environments:
- **If Browserbase API keys exist** (BROWSERBASE_API_KEY and BROWSERBASE_PROJECT_ID in .env file): Uses remote Browserbase environment
- **If no Browserbase API keys**: Falls back to local Chrome browser
- **No user prompting**: The selection happens automatically based on available configuration

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · setup.json (reported line 29)May include surrounding context.

json
### First: Environment Selection (Local vs Remote)

The skill automatically selects between local and remote browser environments:
- **If Browserbase API keys exist** (BROWSERBASE_API_KEY and BROWSERBASE_PROJECT_ID in .env file): Uses remote Browserbase environment
- **If no Browserbase API keys**: Falls back to local Chrome browser
- **No user prompting**: The selection happens automatically based on available configuration

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The login example normalizes entering usernames and passwords into browser automation without warning about secret handling, reuse of authenticated sessions, or risks from the preserved Chrome profile. In this skill context, that is meaningfully dangerous because browser automation may expose credentials in logs, screenshots, prompts, shell history, or persisted session cookies, enabling account compromise or unintended actions in authenticated contexts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The download example shows automatic retrieval of a remote file to a local directory but does not emphasize that browsing to a file URL causes a local write. In a browser automation skill, this increases risk of silent storage of untrusted content, accidental retention of sensitive files, and downstream exposure if other tools process the downloaded files automatically.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The reference explicitly states that downloads start automatically and are written to ./agent/downloads without any file type restrictions or an up-front user warning. In a browser automation skill, this can cause silent persistence of untrusted content to disk, including potentially dangerous executables or sensitive files, especially when navigation or actions are driven by natural language and remote web content.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill advertises very broad activation criteria for general browsing, extraction, screenshots, form filling, and web-app interaction without any scoping, consent, or sensitivity boundaries. That increases the chance the agent will invoke this skill for routine requests that may involve sensitive sites or data, expanding the attack surface and making misuse more likely.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

The file specifies "Google Chrome browser" as required, and later instructs the user to ensure Chrome is installed. This imposes a specific software/environment choice in natural language without offering alternatives or explaining why that locale/environment restriction is necessary.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

This is a JSON manifest file, so vague-trigger checks apply. The repeated examples using the generic command phrase "browser navigate" describe how to invoke the skill but do not specify whether activation is limited to this exact command, what variants are supported, or any exclusion conditions, leaving trigger scope ambiguous.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.