Back to skill

Security audit

stealthy-auto-browse

Security checks across malware telemetry and agentic risk

Overview

The skill is a powerful stealth browser automation tool, but its high-risk capabilities are clearly disclosed, purpose-aligned for authorized QA/security testing, and paired with practical safety guidance.

Install only if you need detection-resistant browser automation for systems you own or are authorized to test. Keep the API and VNC bound to localhost, set AUTH_TOKEN, use dedicated test accounts, audit any loader YAML before mounting it, avoid real production sessions, and delete persistent profile data when testing ends.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Description-Behavior Mismatch

Medium
Confidence
88% confidence
Finding
The documentation repeatedly frames the tool as authorized QA, but it also provides polished screenshot-plus-extract and script-mode workflows that directly support high-volume page extraction. In a tool explicitly designed to resist bot detection, those extraction workflows materially increase dual-use risk by making unauthorized scraping and content harvesting easier.

Context-Inappropriate Capability

Medium
Confidence
80% confidence
Finding
The skill exposes broad cookie and local/session storage read-write primitives that enable session hijacking, impersonation, and persistence manipulation beyond what is strictly necessary for anti-bot QA. In combination with stealth browsing and unauthenticated or weakly protected deployments, these APIs can be abused to alter authenticated state or exfiltrate live session material.

Context-Inappropriate Capability

Medium
Confidence
90% confidence
Finding
URL-triggered loaders execute automatically on navigation and can run state-changing steps like eval, clicks, and form fills without an additional confirmation at execution time. This creates hidden automation behavior that can surprise operators, expand attack surface via untrusted loader files, and cause unintended actions on visited pages.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.