Back to skill

Security audit

Web Research Assistant

Security checks for vulnerabilities and agentic risk

Overview

This skill is a web research helper, but it explicitly promotes bypassing paywalls, CAPTCHA, geographic restrictions, and blocked AI access.

Review carefully before installing. Use only for authorized web research and avoid paywalled, CAPTCHA-protected, geoblocked, or otherwise restricted content unless you have explicit rights to access it through BrowserAct. Do not place sensitive business, incident, legal, or credential material in queries unless sending that data to BrowserAct is acceptable.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (13)

Tainted flow: 'BROWSERACT_MCP_TOKEN' from os.environ.get (line 19, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/research.py (reported line 52)May include surrounding context.

python
}
    }
    
    response = requests.post(
        MCP_SERVER_URL,
        headers={
            "Authorization": f"Bearer {BROWSERACT_MCP_TOKEN}",

Ssd 4

High
Category
Not specified by scanner
Confidence
92% confidence
Finding

The narrative normalizes using the skill when direct web access is restricted or blocked, framing restriction evasion as a standard feature rather than an exceptional, authorized workflow. In a web-research skill, this context materially increases risk because the tool is aimed at acquiring information from sites that are actively denying access.

Content

No source excerpt is available for this finding.

Ssd 2

High
Category
Not specified by scanner
Confidence
94% confidence
Finding

Phrases like 'auto-recovery,' 'global access,' and similar wording soften and normalize what appears to be evasion of access controls. This is dangerous because it obscures the true security and compliance implications, making operators more likely to invoke the skill for restricted targets without informed approval.

Content

No source excerpt is available for this finding.

Ssd 2

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The guidance says to use the skill when paywalls prevent data extraction, which semantically directs users toward obtaining gated content without authorization. In context, that is a clear misuse pattern because paywalls are an access control, and encouraging workarounds can facilitate content theft and contractual violations.

Content

No source excerpt is available for this finding.

Ssd 2

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The feature list claims built-in mechanisms to avoid human verification challenges and regional IP restrictions, which is explicit anti-protection bypass language. This is dangerous because it advertises operational capability to evade safeguards designed to limit automated or unauthorized access.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The description explicitly promises circumvention of CAPTCHA and regional/IP restrictions without any safety rationale, authorization checks, or user consent flow. That is dangerous because it directly frames the skill as a tool for evading access controls, which can enable unauthorized scraping, policy violations, and abusive collection of gated content.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding

The skill advertises behavior that requires environment access, network use, and file output, but it does not declare an explicit tool scope such as permissions or allowed-tools. This weakens least-privilege controls and can cause the host agent to grant broader capabilities than users expect, especially for a skill that performs outbound web access and writes research reports.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill describes bypassing geographic restrictions and anti-bot protections but does not warn users about the legal, contractual, and policy implications of doing so. In this context, omission of warnings is risky because the skill is specifically positioned as a fallback when normal access is blocked, making misuse more likely.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The documentation claims the skill avoids CAPTCHA and human verification problems, but the file provides no substantiation, safeguards, or implementation detail for such a sensitive capability. Unverified claims of anti-bot bypass are dangerous because they encourage use against protected services and obscure compliance, legal, and abuse risks.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
83% confidence
Finding

This script performs external network transmission of user-supplied research queries and derived options to a remote service. In the context of a tool designed to bypass restricted web access, this increases risk because users may assume local processing while the tool actually sends potentially sensitive research topics outside the environment.

Content

Scanner excerpt · scripts/research.py (reported line 52)May include surrounding context.

python
}
    }
    
    response = requests.post(
        MCP_SERVER_URL,
        headers={
            "Authorization": f"Bearer {BROWSERACT_MCP_TOKEN}",

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill transmits user-provided queries and search parameters to an external third-party service without an explicit user-facing disclosure or consent step at execution time. If users include sensitive prompts, proprietary topics, credentials, or incident details in queries, that data leaves the local environment and may be retained or processed externally.

Content

No source excerpt is available for this finding.

Dynamic import via __import__()

Medium
Category
Dangerous Code Execution
Confidence
75% confidence
Finding

Dynamic import() can load arbitrary modules at runtime, bypassing static analysis and potentially importing malicious code.

Content

Scanner excerpt · scripts/research.py (reported line 125)May include surrounding context.

python
"""
    report = f"# Web Research Report\n\n"
    report += f"**Query**: {query}\n\n"
    report += f"**Date**: {__import__('datetime').datetime.now().strftime('%Y-%m-%d %H:%M:%S')}\n\n"
    
    report += "## Executive Summary\n\n"
    report += f"{extracted['summary']}\n\n"

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
75% confidence
Finding

The manifest describes a web research assistant that searches the internet via BrowserAct, but it does not mention reading credentials from the environment. While authenticating to BrowserAct may be operationally necessary, accessing environment-stored secrets is still an additional capability beyond the stated user-facing purpose.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.