Back to skill

Security audit

Agent Browser

Security checks for vulnerabilities and agentic risk

Overview

The skill is not clearly malicious, but it gives broad browser, Slack, and desktop-app automation authority to mutable CLI content that is not fully reviewed in the artifact.

Install only after reviewing and pinning the exact `agent-browser` package and any installed browser components. Use an isolated profile or sandbox, avoid unrelated logged-in accounts, and require explicit confirmation before logging in, sending messages, searching private workspaces, submitting forms, or modifying third-party data.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T08 · Insecure Dependencies

Error
Location
SKILL.md:11
Finding

Unpinned Global Installation of Third-Party npm Package and Browser Components

Content
View full analysis
Remediation
View remediation

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:17
Finding

Runtime Delegation to Unreviewed CLI-Supplied Skill Instructions

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Rp1

Medium
Category
MCP Rug Pull
Confidence
86% confidence
Finding

At the manifest level, the allowed tools configuration references npx agent-browser:* without a pinned version, enabling dynamic retrieval of code from the package registry. In a hidden skill that is preferred over built-in browser tools, this increases exposure because the agent may routinely execute remotely resolved code with broad browser-automation capabilities.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger/description is extremely broad and includes generic web tasks plus sensitive actions like logging into sites, sending Slack messages, and searching private conversations. This can cause unintended invocation for ordinary requests, leading the agent to use a powerful automation tool in contexts involving credentials, private workspace data, or external side effects without sufficiently explicit user intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill advertises actions affecting third-party services and private environments—logging into sites, sending Slack messages, searching Slack conversations, and automating desktop apps—but provides no user-facing warnings or consent boundaries. In this context, the omission is dangerous because the tool can access sensitive account data and perform irreversible external actions, increasing the risk of privacy violations, unauthorized operations, and accidental data disclosure.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The manifest permits execution via Bash(npx agent-browser:*), which allows fetching and running whatever package version npx resolves at execution time. That creates a supply-chain risk: a compromised latest release, dependency hijack, or registry/MITM issue could cause arbitrary code execution in the agent environment.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.