Back to skill

Security audit

Agent Browser

Security checks across malware telemetry and agentic risk

Overview

This skill is a real browser-automation wrapper, but it asks for very broad authority over websites, logins, desktop apps, Slack, sessions, and externally supplied workflow instructions.

Install only if you intentionally want an agent to automate browsers and related apps with access to logged-in sessions. Review the npm package and CLI-provided workflow content, avoid using it with sensitive accounts unless necessary, and require explicit confirmation before sending messages, submitting forms, or using stored authentication.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

High
Confidence
96% confidence
Finding
The skill description and trigger language are extremely broad, using catch-all phrases like any task requiring programmatic web interaction and prefer agent-browser over any built-in browser automation or web tools. This can cause the skill to activate in many unrelated contexts, giving a powerful browser automation capability unnecessary access to websites, authenticated sessions, Slack, Electron apps, and cloud browsers, which raises the risk of unintended actions or data exposure.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.