Back to skill

Security audit

Goodreads (Read + Write)

Security checks for vulnerabilities and agentic risk

Overview

The skill is openly built for Goodreads read/write automation, but it stores a reusable login session and uses stealth browser automation with weakened browser isolation to modify account data.

Install only if you are comfortable giving this skill ongoing access to an authenticated Goodreads browser session and letting it change your Goodreads ratings, shelves, reviews, dates, and progress. Use a dedicated virtual environment and OS user where practical, avoid shared machines, protect or periodically delete 'scripts/.browser-data', review every write action before running it, and consider removing stealth/no-sandbox behavior or pinning dependencies before use.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:34
Finding

Unpinned Third-Party Dependencies Create a Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:34-38; duplicated in references/SETUP.md:19-23
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Medium

Vulnerable Code

From SKILL.md:34-38:

bash
# Install dependencies
pip install playwright playwright-stealth
playwright install chromium

Equivalent installation instructions appear in references/SETUP.md:19-23:

bash
### 2. Install Python dependencies

```bash
pip install playwright playwright-stealth
playwright install chromium
text

### Technical Analysis

The installation instructions retrieve mutable latest releases of `playwright`, `playwright-stealth`, their transitive dependencies, and a Chromium binary without a version lock file, exact version constraints, or package hashes.

These dependencies execute with the privileges of the user installing or running the Skill. At runtime, they also interact with the persistent browser profile containing the authenticated Goodreads session. If a dependency release, dependency account, package registry response, or transitive package is compromised, attacker-controlled installation or import code could execute locally.

No alternate package registry, obvious typosquatting, or intentionally malicious package was found. This is therefore a supply-chain hardening deficiency rather than evidence that the named dependencies are currently malicious.

### Attack Path

1. A threat actor compromises a dependency or one of its transitive dependencies, or publishes a malicious release through a compromised maintainer account.
2. A user follows the documented setup and runs the unpinned `pip install` command.
3. Package resolution selects the compromised release because no reviewed version or hash is enforced.
4. Malicious installation hooks or imported runtime code execute with the user’s privileges.
5. The malicious code can access files readable by that user, interact with the browser process, inspect the persistent Goodreads 
...[truncated 676 chars]
Remediation
View remediation

Remediation Suggestions

  1. Create a reviewed dependency lock file containing exact versions for all direct and transitive Python dependencies.
  2. Generate and enforce cryptographic package hashes, for example:
bash
python3 -m pip install --require-hashes -r requirements.txt
  1. Pin the Playwright package version so that the associated Chromium download is reproducible.
  2. Document the expected Chromium revision and verify downloaded browser artifacts through Playwright’s supported integrity mechanisms.
  3. Install dependencies inside a dedicated, non-privileged virtual environment.
  4. Avoid running pip or Playwright installation commands with sudo.
  5. Use automated dependency scanning and review updates before changing locked versions.

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/goodreads-writer.py:49
Finding

Chromium Process Sandbox Is Explicitly Disabled

Content
View full analysis

Vulnerability Details

File Location: scripts/goodreads-writer.py:49-65
Vulnerability Type: T09: Insecure Skill Coding Practices
Risk Level: Medium

Vulnerable Code

python
context = await playwright.chromium.launch_persistent_context(
    user_data_dir=USER_DATA_DIR,
    headless=headless,
    viewport={"width": 1280, "height": 800},
    user_agent=(
        "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) "
        "AppleWebKit/537.36 (KHTML, like Gecko) "
        "Chrome/131.0.0.0 Safari/537.36"
    ),
    locale="en-US",
    timezone_id="America/New_York",
    args=[
        "--disable-blink-features=AutomationControlled",
        "--no-sandbox",
    ],
    ignore_default_args=["--enable-automation"],
)

Technical Analysis

The --no-sandbox argument disables Chromium’s process and renderer sandbox. That sandbox is a major defense-in-depth boundary intended to limit the host-level consequences of a browser renderer compromise.

The Skill processes remote Goodreads pages and associated web resources while using a persistent authenticated browser profile. Browser content is not trusted merely because the primary page belongs to Goodreads: a compromised site, third-party resource, malicious advertisement, or browser vulnerability could expose the renderer to hostile content.

Disabling the sandbox is not required by the declared Goodreads read/write functionality. It therefore exceeds the minimum browser privileges needed for normal execution and unnecessarily weakens isolation between remote web content and the local user environment.

Attack Path

  1. The Skill launches Chromium with --no-sandbox.
  2. Chromium loads Goodreads pages and their remote subresources.
  3. Compromised or malicious remote content exploits a Chromium renderer or browser vulnerability.
  4. Because the process sandbox is disabled, the exploit encounters a substantially weaker isolation boundary.
  5. Attacker-controlled code may access resources availabl ...[truncated 894 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the --no-sandbox Chromium argument:
python
args=[
    "--disable-blink-features=AutomationControlled",
]
  1. Run Chromium under an unprivileged operating-system account.
  2. If the deployment environment does not support Chromium sandboxing, enable the required user namespaces and kernel features rather than disabling the sandbox.
  3. For constrained container deployments, use a hardened container with:
    • No host filesystem mounts beyond required storage.
    • A read-only root filesystem where practical.
    • Dropped Linux capabilities.
    • No privileged mode.
    • Restricted outbound network access.
    • A dedicated volume for the browser profile.
  4. Keep Chromium and Playwright on reviewed, patched versions.
  5. Restrict permissions on scripts/.browser-data to the owning user because it contains reusable authenticated session material.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (10)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

A second description-behavior mismatch is present: the skill is marketed as 'full Goodreads integration' even though static analysis says major declared read capabilities are not implemented. Overstated capabilities can cause over-broad trust, unnecessary permission grants, and operational confusion around what data is accessed or what actions can actually be taken.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

A second description-behavior mismatch is present: the skill is marketed as 'full Goodreads integration' even though static analysis says major declared read capabilities are not implemented. Overstated capabilities can cause over-broad trust, unnecessary permission grants, and operational confusion around what data is accessed or what actions can actually be taken.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill advertises and documents network access, environment-variable use, scraping, and browser automation, but it does not declare an explicit tool scope such as allowed tools or permissions. That makes it harder to constrain execution and increases the chance the agent can access broader capabilities than users or the platform expect.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The invocation guidance says to use the skill for broad book-, reading-list-, and rating-related requests, which is wider than necessary for an account-linked Goodreads integration. Over-broad triggering can cause the agent to invoke a networked/account-writing skill for generic book questions that could be answered without external access, increasing privacy and account-modification risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill documents multiple write operations—rating, shelving, reviews, dates, and progress updates—without a prominent warning that these commands change a user's Goodreads account data. In an agent setting, insufficient disclosure around state-changing actions raises the risk of unintended or insufficiently consented account modifications.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 165)May include surrounding context.

| currently-reading | Currently Reading | | | read | Read | |

Output includes "verified": true/false — RSS auto-confirms after action.

bash
$W shelf 186190 read                # Move to "Read"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The setup guide states that browser cookies persist for weeks to months via stealth mode, but it does not clearly warn users that these session artifacts may grant ongoing authenticated access to their Goodreads account if the local profile is exposed. In a skill that automates account write actions, persistent session storage materially increases the risk of unauthorized actions from local compromise, shared machines, or accidental inclusion of browser data in backups.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script deliberately masks browser automation by removing Playwright automation flags, spoofing a desktop Chrome fingerprint, and optionally applying a stealth library to bypass anti-bot controls. In a Goodreads integration skill, this exceeds normal automation needs and undermines site bot-detection safeguards, creating compliance and abuse risk if the agent performs actions at scale or against service expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

This code hard-codes locale="en-US" and timezone_id="America/New_York" for all browser sessions. The file does not offer the user any choice or document a justified region-specific constraint, which conflicts with the policy against forcing a language/locale setting without opt-in.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

The docstring for cmd_shelf says it can move a book to 'read, currently-reading, to-read, or custom'. In code, target_aria is only resolved from a fixed SHELF_ARIA mapping, and unknown shelf names immediately error out, so custom shelves are not actually supported.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.