Midscene Automations Skills for Browser with Bridge

Security checks across malware telemetry and agentic risk

Overview

This appears to be a legitimate Chrome automation skill, but it gives an agent broad control over your logged-in browser without enough safety scoping.

Install only if you are comfortable letting the agent operate your real Chrome session. Use a separate Chrome profile or VM, avoid banking, healthcare, admin consoles, private messages, and MFA pages, verify the Midscene extension and npm package source, and require explicit approval before the agent acts on logged-in sites or extracts private data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
98% confidence
Finding
This skill explicitly states that it connects to the user's desktop Chrome browser and preserves cookies, sessions, and login state, yet the description does not provide a clear user-facing warning about the sensitivity of that access or the risk of extracting data and performing actions in authenticated contexts. In a browser-automation skill, this omission is dangerous because users may invoke it without fully understanding that the agent can act as them on logged-in sites and access private account data.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal