Back to skill

Security audit

meta-agent-browser-core

Security checks for vulnerabilities and agentic risk

Overview

The skill is not clearly malicious, but it asks agents to use broad self-evolving browser-agent behavior without enough boundaries or user controls.

Review this skill before installing. It does not show exfiltration or destructive behavior, but it is vague and self-evolving: only use it in contexts where local note persistence is acceptable, avoid letting it store secrets or private browsing details, and require explicit user approval before any high-impact browser, account, posting, or long-running orchestration actions.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Tp4

High
Category
MCP Tool Poisoning
Confidence
79% confidence
Finding
The skill markets itself as an enhanced meta-skill with self-verification, orchestration, reflection, and continuous self-evolution, but the manifest does not clearly define concrete boundaries, behaviors, or safeguards. That gap can cause operators to over-trust the skill, while hidden or external behaviors such as memory writing, orchestration, or autonomous refinement may occur without explicit disclosure.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The invocation guidance says to directly call the skill for the entire 'agent-browser-core' task domain, with no trigger constraints, scope limits, or approval conditions. Broad activation criteria increase the risk of accidental invocation in inappropriate contexts, privilege creep, and unsafe use of any hidden orchestration or persistence features described elsewhere in the skill.

Missing User Warnings

Low
Confidence
74% confidence
Finding
The script writes persistent data to a local JSON file without any notice, consent mechanism, retention control, or validation of what may be stored in the free-form note field. In an agent-skill context, silent persistence can accumulate sensitive operational details over time and create a privacy or information exposure risk if the file is later accessed by other local users, tools, or processes.

Static analysis

No suspicious patterns detected.