Back to skill

Security audit

Agent Browser Clawdbot Local

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent browser-automation helper, but users should treat saved auth state, cookies, storage, and the global npm install as sensitive operational risks.

Install only from the expected npm package/publisher, prefer pinning a reviewed version, and be cautious with --with-deps or elevated privileges. Treat saved auth state, cookies, and local storage as credentials: use test or least-privilege accounts where possible, keep state files out of source control, restrict access to them, and delete them when no longer needed.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:198
Finding

Unpinned Global Dependency Installation Creates Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 198-200
Vulnerability Type: Unpinned third-party package installation
Risk Level: Medium

bash
npm install -g agent-browser
agent-browser install                     # Download Chromium
agent-browser install --with-deps         # Linux: + system deps

Technical Analysis

The installation instructions retrieve the agent-browser npm package without specifying an exact version or integrity value. Consequently, the installed code depends on whichever package release the registry resolves at installation time rather than a release that was reviewed with this Skill.

The package is installed globally and its executable is subsequently invoked to download Chromium or install additional system dependencies. npm package lifecycle scripts and the invoked installer can execute code with the permissions of the user running these commands. If the package, maintainer account, registry publication process, or a transitive dependency is compromised, the downloaded code could differ materially from the code reviewed when the Skill was published.

The repository reference in the documentation does not cryptographically bind the npm installation to a specific reviewed source revision. The project contains no lockfile, package integrity hash, provenance verification procedure, or version constraint that mitigates this mutable-dependency risk.

Attack Path

  1. An attacker compromises the npm package, a maintainer account, or a dependency included by a future package release.
  2. The attacker publishes a malicious or backdoored version under the expected package name.
  3. A user follows the documented npm install -g agent-browser command.
  4. npm resolves and installs the attacker-controlled version because no exact version or integrity constraint is present.
  5. Malicious package lifecycle code may execute during installation, or the payload may execute when the ...[truncated 1022 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin agent-browser to a reviewed exact version rather than relying on the registry's current release.
  2. Verify npm provenance, package signatures where available, and published integrity information before installation.
  3. Document the expected package version, source revision, Chromium artifact, checksums, and publisher identity.
  4. Prefer a project-local installation with a committed lockfile over global installation, reducing system-wide exposure and ensuring deterministic dependency resolution.
  5. Disable npm lifecycle scripts during initial package retrieval where operationally possible, then review any required scripts before explicitly running them.
  6. Perform installation and browser downloads in a sandbox, container, or otherwise restricted account.
  7. Do not run --with-deps with elevated privileges until the exact installer version and its system-level actions have been reviewed.
  8. Periodically review and deliberately update the pinned version instead of accepting automatic mutable updates.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill explicitly documents saving and loading browser authentication state, which commonly includes cookies and storage tokens that can grant account access if reused. In an agent-oriented automation context, presenting this capability without any warning about sensitivity, storage protection, scope limitation, or secret-handling increases the risk that users or downstream agents will persist live session material insecurely.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill exposes commands to read and modify cookies and local storage, which can reveal or alter session identifiers, CSRF tokens, and application state. In a browser automation skill meant for AI agents, omitting privacy and integrity warnings makes accidental credential exposure, account takeover, or state tampering more likely, especially if agents are pointed at real user environments.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.