Back to skill

Security audit

podman-browser

Security checks for vulnerabilities and agentic risk

Overview

This skill does what it claims, but it runs arbitrary web pages in a weakened browser/container isolation setup that users should review before installing.

Install only if you are comfortable running a containerized browser that visits supplied URLs with reduced isolation. Avoid using it on sensitive internal sites, prefer trusted URLs, and consider removing host IPC, enabling Chromium sandboxing, and using a prebuilt image pinned by digest before regular use.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
browse.js:119
Finding

Runtime Dependencies Are Retrieved and Executed Without Immutable Verification

Content
View full analysis

Vulnerability Details

File Location: browse.js:5-6, browse.js:119-122
Vulnerability Type: Supply-chain exposure through mutable container and npm dependencies
Risk Level: Medium

Vulnerable Code

js
const IMAGE = 'mcr.microsoft.com/playwright:v1.50.0-noble';
const PLAYWRIGHT_VERSION = '1.50.0';
js
IMAGE,
'/bin/bash', '-c',
`cd /tmp && npm init -y >/dev/null 2>&1 && npm install playwright@${PLAYWRIGHT_VERSION} >/dev/null 2>&1 && node -e '${playwrightScript.replace(/'/g, "'\\''")}'`

Technical Analysis

Each invocation executes npm install playwright@1.50.0 inside a newly created container. Although an explicit package version is specified, the installation does not use a committed lockfile, a verified package integrity hash, or an internally reviewed package artifact. The npm client may also execute package lifecycle scripts during installation.

The Playwright container is identified by the mutable tag v1.50.0-noble rather than an immutable image digest. Consequently, the effective image executed by the skill could change if that tag is replaced or the upstream registry is compromised.

This behavior creates a supply-chain trust dependency at runtime: code retrieved after the project has been audited is installed and executed automatically.

Attack Path

  1. An attacker compromises the upstream npm package, npm registry resolution path, container registry, or mutable image tag.
  2. A user invokes browse.js for an otherwise legitimate browsing operation.
  3. Podman retrieves the mutable container image when it is unavailable locally or an updated image is requested.
  4. The container runs npm install playwright@1.50.0 without validating a project-controlled integrity record.
  5. Altered package code or lifecycle scripts execute inside the container.
  6. The malicious dependency can access the container's network, environment, browser process, and generated browsing res ...[truncated 774 chars]
Remediation
View remediation

Remediation Suggestions

  1. Build and publish a reviewed application image that already contains the required Playwright package instead of installing it on every invocation.
  2. Pin the container image by immutable digest, for example:
    js
    const IMAGE = 'mcr.microsoft.com/playwright@sha256:<verified-digest>';
    
  3. Commit a package-lock.json generated from a trusted environment and use npm ci rather than npm install.
  4. Verify dependency integrity in CI and before image publication.
  5. Disable lifecycle scripts with --ignore-scripts if Playwright installation does not require them in the selected image.
  6. Scan the finished image and dependency tree for known vulnerabilities.
  7. Prefer an internally mirrored or allowlisted registry and enforce image-signature verification.
  8. Define a controlled update process so dependency and image changes receive review before deployment.

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
browse.js:72
Finding

Arbitrary Web Content Is Processed with Chromium Sandbox Disabled and Host IPC Shared

Content
View full analysis

Vulnerability Details

File Location: browse.js:72-75, browse.js:113-116
Vulnerability Type: Unnecessary weakening of browser and container isolation
Risk Level: Medium

Vulnerable Code

js
const browser = await chromium.launch({
    headless: true,
    args: ['--no-sandbox', '--disable-setuid-sandbox']
});
js
const podmanArgs = [
    'run', '--rm', '-i',
    '--ipc=host',
    '--init',

Technical Analysis

The tool is designed to load arbitrary and potentially attacker-controlled websites. Chromium is nevertheless launched with both --no-sandbox and --disable-setuid-sandbox, disabling a major defense boundary intended to contain a compromised renderer process.

The container is also started with --ipc=host. This places it in the host IPC namespace rather than a private container IPC namespace. A process that compromises Chromium or another process in the container may consequently receive access to IPC resources visible in that namespace, subject to operating-system permissions.

Containers provide an additional isolation layer, but they are not a complete substitute for Chromium's process sandbox. Combining a disabled browser sandbox with host IPC sharing unnecessarily increases the consequences of a browser vulnerability.

Attack Path

  1. An attacker hosts a malicious page or compromises a page that the user intends to browse.
  2. The user supplies that URL to browse.js.
  3. Chromium loads and executes the attacker's HTML, JavaScript, media, fonts, and other browser-supported content.
  4. The page exploits a Chromium renderer or browser-process vulnerability applicable to the pinned browser version.
  5. Because the Chromium sandbox is disabled, the exploit does not need to cross the normal renderer sandbox boundary to control the browser process environment.
  6. Code executing in the container inspects or interacts with IPC resources exposed through `--ipc=ho ...[truncated 993 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove --ipc=host and retain Podman's default private IPC namespace.
  2. If Chromium requires additional shared memory, allocate a bounded private /dev/shm size instead of sharing the host namespace.
  3. Run the container and Chromium as a dedicated non-root user.
  4. Remove --no-sandbox and --disable-setuid-sandbox, then configure the image so Chromium's supported sandbox can operate.
  5. Drop all unnecessary Linux capabilities and add back only capabilities proven to be required.
  6. Use a read-only root filesystem with narrowly scoped writable temporary filesystems.
  7. Apply Podman's default or stricter seccomp and SELinux/AppArmor confinement.
  8. Restrict outbound network access to destinations required for the requested browsing task where operationally possible.
  9. Regularly update the reviewed Chromium and Playwright versions to receive browser security fixes.
  10. Consider URL validation or destination policies to prevent access to loopback, link-local, and private infrastructure if untrusted users can control the URL.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Privileged Container / Container Escape

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Documenting use of --ipc=host indicates the container shares the host IPC namespace, which weakens isolation and can increase the blast radius of a compromised browser or malicious page rendered inside the container. In a skill explicitly designed to browse arbitrary remote content, this context makes the risk more serious because untrusted web content is being processed in a less-isolated container environment.

Content

Scanner excerpt · README.md (reported line 110)May include surrounding context.

md
- First run pulls the container image (~1.5GB)
- Each run starts a fresh container (clean but takes ~10-15s)
- Uses `--ipc=host` for Chromium stability
- Uses `--init` to handle zombie processes

## License

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 67)May include surrounding context.

md
- `SKILL.md` - This documentation

Privileged Container / Container Escape

High
Category
Privilege Escalation
Confidence
93% confidence
Finding

Using --ipc=host gives the container access to the host IPC namespace, reducing isolation between the browser container and the host. In the context of a skill designed to fetch and render arbitrary web pages, this increases the blast radius of any browser, Playwright, or container breakout vulnerability and is therefore a real security issue, even if intended for Chromium stability.

Content

Scanner excerpt · SKILL.md (reported line 72)May include surrounding context.

md
## Notes

- First run will pull the container image (~1.5GB)
- Uses `--ipc=host` for Chromium stability
- Uses `--init` to handle zombie processes
- Sandbox disabled when running as root (fine for trusted sites)
- Each run starts a fresh container (clean but takes ~10-15s)

Privileged Container / Container Escape

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

The container is launched with --ipc=host, which shares the host IPC namespace with the browser container. This weakens isolation for code that visits attacker-controlled web pages and dynamically installs/runs Playwright inside the container, increasing the blast radius if the browser or container is compromised and enabling interaction with host/shared-memory IPC resources.

Content

Scanner excerpt · browse.js (reported line 119)May include surrounding context.

js
// Run Playwright in Podman container
const podmanArgs = [
    'run', '--rm', '-i',
    '--ipc=host',
    '--init',
    '-e', `TARGET_URL=${url}`,
    '-e', `WAIT_MS=${waitMs}`,

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 29)May include surrounding context.

cp -r podman-browser ~/.openclaw/workspace/skills/

text

Create a symlink to make it available in your PATH:

```bash
ln -sf ~/.openclaw/workspace/skills/podman-browser/browse.js ~/.local/bin/podman-browse

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 13)May include surrounding context.

Installation

Create a symlink for easy access:

bash
chmod +x browse.js

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation explicitly instructs users to browse arbitrary URLs and notes that first run will pull a large remote container image, but it does not clearly warn that this causes outbound network requests to untrusted destinations and execution of software obtained from a remote registry. In a browser-automation skill, that omission matters because users may expose internal network reachability or trust remote code/images without understanding the risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The notes mention --ipc=host and that the browser sandbox may be disabled when running as root, but they frame these as operational details rather than security-sensitive settings. For a tool that loads arbitrary web content, failing to warn users about reduced isolation materially increases risk if a browser or container escape vulnerability is exploited.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file documents usage of a headless browser that navigates to provided URLs and fetches rendered content, but it does not explicitly warn users that using the skill causes external network access to third-party sites. Because markdown files should disclose behaviors affecting privacy or system integrity, a brief warning about outbound requests and remote content execution would improve user awareness.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
browse.js:130