Back to skill

Security audit

Browser Secure

Security checks for vulnerabilities and agentic risk

Overview

This browser automation skill is not covertly malicious, but it handles vault credentials and browser sessions with weak scoping and approval controls that need review.

Install only if you are comfortable giving this tool access to authenticated browser sessions and password-manager material. Prefer a dedicated automation Chrome profile, avoid personal or regulated accounts, leave audit webhook disabled unless the destination is fully trusted, do not use --yes or --skip-approval for sensitive sites, and avoid auto-vault/manual credential entry until origin binding, approval, and password-input issues are fixed.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (6)

T09 · Insecure Skill Coding Practices

Error
Location
src/browser/secure-session.ts:299
Finding

Vault credentials may be injected into an untrusted origin after a redirect

Content
View full analysis
{ if (!page) return; try { const usernameSelectors = [ 'input[type="email"]', 'input[name="email"]', 'input[name="username"]', 'input[id="username"]', 'input[id="login"]', 'input[name="login"]' ]; for (const selector of usernameSelectors) { const field = await page.$(selector); if (field) { await field.fill(username); break; } } const passwordInput = await page.$('input[type="password"]'); if (passwordInput) { await passwordInput.fill(password); logAction('fill_password', { method: 'vault_injected' }, { userApproved: true }); } await takeScreenshot('login'); } catch (e) { throw new Error(`Failed to fill login ...[truncated 1569 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
src/browser/secure-session.ts:548
Finding

Destructive actions can evade classification and the purported 2FA check accepts arbitrary digits

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
src/security/audit.ts:119
Finding

Audit webhook exports sensitive session metadata without applying network restrictions

Content
View full analysis
{ const config = loadConfig(); const auditConfig = config.security.audit; if (auditConfig.mode === 'file') { return; } const webhookUrl = auditConfig.webhook?.url; if (!webhookUrl) { return; } try { const headers: Record = { 'Content-Type': 'application/json', ...(auditConfig.webhook?.headers || {}) }; const response = await fetch(webhookUrl, { method: 'POST', headers, body: JSON.stringify(session) }); if (!response.ok) { console.error(`Audit webhook failed: ${response.status} ${response.statusText}`); } } catch (e) { console.error(`Audit webhook error: ${e}`); } } ``` Audit records include values generated by these call sites: ```ts logAction('navigate', { url }); logAction('act', { instruction: action }); logAction('extract', { instruction, schema }); ``` ### Technical Analysis The webhook transmits the complete audit session to an arbitrary configured URL. The payload can contain visited URLs, site identifiers, action instructions, extraction schemas, screenshot paths, session identifiers, and approval tokens. Unlike browser navigation, this code does not call `validateUrl()` or `isHostAllowed()`. It does not require HTTPS, enforce an allowlist, prohibit localhost or private addresses, validate DNS resolution, or restrict redirects. Webhook support is documented and disabled by default, so this is not covert telemetry. Nevertheless, once enabled, it exceeds the protection offered by the adverti ...[truncated 1004 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
src/vault/discovery.ts:91
Finding

Single-site credential discovery decrypts and loads the entire Bitwarden vault

Content
View full analysis
{ const name = item.name.toLowerCase(); const notes = (item.notes || '').toLowerCase(); return name.includes(siteKey) || name.includes(domain.replace('.', '')) || domain.includes(name.replace(/\s+/g, '').toLowerCase()) || notes.includes(domain); }); return results.slice(0, 10); } catch (e) { console.error('Failed to search Bitwarden:', e); return []; } } ``` ### Technical Analysis The function executes `bw list items` without a search constraint. Bitwarden CLI output may contain complete login objects, including usernames, passwords, notes, and custom fields. The entire vault is parsed into the Node.js process before local filtering. Credential discovery for a single website does not require all unrelated vault secrets. This violates least privilege and increases the exposure window and memory footprint of decrypted secrets. ### Attack Path 1. The user unlocks Bitwarden and starts auto-vault discovery for one domain. 2. The Skill runs `bw list items` for the entire vault. 3. All returned vault objects are decrypted and loaded into process memory. 4. A compromised dependency, debugger, process dump, crash collector, or same-user memory inspection captures the in-memory data. 5. Credentials unrelated to the requested site are exposed. ### Impact Assessment The potential exposure includes all Bitwa ...[truncated 227 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/onboarding.js:94
Finding

Setup can retrieve and execute unpinned package code through npx

Content
View full analysis
{ try { const result = execSync('npx playwright --version', { stdio: ['pipe', 'pipe', 'ignore'], encoding: 'utf8' }); return result.includes('Version'); } catch { return false; } }, required: true, autoFixable: true, installCmd: () => 'npx playwright install chromium' }, ``` ```js for (const item of autoFixable) { const cmd = item.installCmd(); if (!cmd) continue; console.log(` Installing ${item.name}...`); try { execSync(cmd, { stdio: 'inherit' }); console.log(` ✅ ${item.name} installed\n`); } catch (err) { console.log(` ⚠️ Failed to install ${item.name}, continuing...\n`); } } ``` ```js const steps = [ { name: 'Installing npm dependencies', cmd: 'npm install' }, { name: 'Building TypeScript', cmd: 'npm run build' }, { name: 'Linking CLI globally', cmd: 'npm link' } ]; ``` ### Technical Analysis The prerequisite check invokes `npx playwright` before local dependencies are installed. If the executable is not available locally, `npx` may resolve and download package code from the configured npm registry and execute it. The repository structure presented during the audit did not include a dependency lockfile, while `package.json` uses version ranges. Therefore, setup resolution is not reproducible and may change after the Skill has been reviewed. This is legitimate installation behavior rather than an intentionally concealed remote payload, but it creates a supply-chain execution risk. ### Attack Path 1. A user runs `npm run setup` on a machine without a local Playwright binary. 2. The prerequisite check invokes `npx playwright --version`. 3. `npx` resolves package conte ...[truncated 630 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
src/vault/discovery.ts:496
Finding

Manual password entry is visibly echoed by the terminal

Content
View full analysis
{ console.log('\n📝 Manual credential entry\n'); const username = await promptUser('Username/Email (press Enter to skip): '); const password = await promptUser('Password (press Enter to skip): '); if (!username && !password) { console.log('No credentials entered. Skipping authentication.'); return null; } const siteKey = extractSiteKey(domain); const credentials: VaultCredentials = {}; if (username) credentials.username = username; if (password) credentials.password = password; const siteConfig: SiteConfig = { vault: 'manual', item: `${siteKey}-manual`, usernameField: username ? 'username' : undefined, passwordField: password ? 'password' : undefined }; ``` The shared prompt implementation uses ordinary `readline`: ```ts function promptUser(question: string): Promise { const rl = readline.createInterface({ input: process.stdin, output: process.stdout }); return new Promise((resolve) => { rl.question(question, (answer) => { rl.close(); resolve(answer.trim()); }); }); } ``` ### Technical Analysis Node.js `readline.question()` does not suppress terminal echo. The password is therefore displayed in plaintext while the user types it. This conflicts with the Skill's goal of secure credential handling. The password remains in JavaScript strings until garbage collected. Although the saved site mapping does not directly persist the entered password, visual disclosure occurs immediately. ### Attack Path 1. Auto-discovery finds no suitable vault credential. 2. The user selects manual credential entry. 3. The terminal displays every ...[truncated 422 chars]
Remediation
View remediation
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (204)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill markets itself as 'secure' and suitable for sensitive/compliance use while documenting capabilities such as reusing real Chrome profiles, closing running Chrome instances, daemonized session reuse, credential discovery, and optional audit webhooks. That creates a dangerous trust mismatch: users may run it against personal or regulated accounts under the assumption of strong safeguards that are only described, not evidenced here. In security-sensitive tooling, overstated security properties materially increase risk because operators may expose cookies, credentials, and browsing state to automation they would otherwise avoid.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill markets itself as 'secure' and suitable for sensitive/compliance use while documenting capabilities such as reusing real Chrome profiles, closing running Chrome instances, daemonized session reuse, credential discovery, and optional audit webhooks. That creates a dangerous trust mismatch: users may run it against personal or regulated accounts under the assumption of strong safeguards that are only described, not evidenced here. In security-sensitive tooling, overstated security properties materially increase risk because operators may expose cookies, credentials, and browsing state to automation they would otherwise avoid.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill markets itself as 'secure' and suitable for sensitive/compliance use while documenting capabilities such as reusing real Chrome profiles, closing running Chrome instances, daemonized session reuse, credential discovery, and optional audit webhooks. That creates a dangerous trust mismatch: users may run it against personal or regulated accounts under the assumption of strong safeguards that are only described, not evidenced here. In security-sensitive tooling, overstated security properties materially increase risk because operators may expose cookies, credentials, and browsing state to automation they would otherwise avoid.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill markets itself as 'secure' and suitable for sensitive/compliance use while documenting capabilities such as reusing real Chrome profiles, closing running Chrome instances, daemonized session reuse, credential discovery, and optional audit webhooks. That creates a dangerous trust mismatch: users may run it against personal or regulated accounts under the assumption of strong safeguards that are only described, not evidenced here. In security-sensitive tooling, overstated security properties materially increase risk because operators may expose cookies, credentials, and browsing state to automation they would otherwise avoid.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill markets itself as 'secure' and suitable for sensitive/compliance use while documenting capabilities such as reusing real Chrome profiles, closing running Chrome instances, daemonized session reuse, credential discovery, and optional audit webhooks. That creates a dangerous trust mismatch: users may run it against personal or regulated accounts under the assumption of strong safeguards that are only described, not evidenced here. In security-sensitive tooling, overstated security properties materially increase risk because operators may expose cookies, credentials, and browsing state to automation they would otherwise avoid.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill markets itself as 'secure' and suitable for sensitive/compliance use while documenting capabilities such as reusing real Chrome profiles, closing running Chrome instances, daemonized session reuse, credential discovery, and optional audit webhooks. That creates a dangerous trust mismatch: users may run it against personal or regulated accounts under the assumption of strong safeguards that are only described, not evidenced here. In security-sensitive tooling, overstated security properties materially increase risk because operators may expose cookies, credentials, and browsing state to automation they would otherwise avoid.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill markets itself as 'secure' and suitable for sensitive/compliance use while documenting capabilities such as reusing real Chrome profiles, closing running Chrome instances, daemonized session reuse, credential discovery, and optional audit webhooks. That creates a dangerous trust mismatch: users may run it against personal or regulated accounts under the assumption of strong safeguards that are only described, not evidenced here. In security-sensitive tooling, overstated security properties materially increase risk because operators may expose cookies, credentials, and browsing state to automation they would otherwise avoid.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill markets itself as 'secure' and suitable for sensitive/compliance use while documenting capabilities such as reusing real Chrome profiles, closing running Chrome instances, daemonized session reuse, credential discovery, and optional audit webhooks. That creates a dangerous trust mismatch: users may run it against personal or regulated accounts under the assumption of strong safeguards that are only described, not evidenced here. In security-sensitive tooling, overstated security properties materially increase risk because operators may expose cookies, credentials, and browsing state to automation they would otherwise avoid.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill markets itself as 'secure' and suitable for sensitive/compliance use while documenting capabilities such as reusing real Chrome profiles, closing running Chrome instances, daemonized session reuse, credential discovery, and optional audit webhooks. That creates a dangerous trust mismatch: users may run it against personal or regulated accounts under the assumption of strong safeguards that are only described, not evidenced here. In security-sensitive tooling, overstated security properties materially increase risk because operators may expose cookies, credentials, and browsing state to automation they would otherwise avoid.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill markets itself as 'secure' and suitable for sensitive/compliance use while documenting capabilities such as reusing real Chrome profiles, closing running Chrome instances, daemonized session reuse, credential discovery, and optional audit webhooks. That creates a dangerous trust mismatch: users may run it against personal or regulated accounts under the assumption of strong safeguards that are only described, not evidenced here. In security-sensitive tooling, overstated security properties materially increase risk because operators may expose cookies, credentials, and browsing state to automation they would otherwise avoid.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill markets itself as 'secure' and suitable for sensitive/compliance use while documenting capabilities such as reusing real Chrome profiles, closing running Chrome instances, daemonized session reuse, credential discovery, and optional audit webhooks. That creates a dangerous trust mismatch: users may run it against personal or regulated accounts under the assumption of strong safeguards that are only described, not evidenced here. In security-sensitive tooling, overstated security properties materially increase risk because operators may expose cookies, credentials, and browsing state to automation they would otherwise avoid.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill markets itself as 'secure' and suitable for sensitive/compliance use while documenting capabilities such as reusing real Chrome profiles, closing running Chrome instances, daemonized session reuse, credential discovery, and optional audit webhooks. That creates a dangerous trust mismatch: users may run it against personal or regulated accounts under the assumption of strong safeguards that are only described, not evidenced here. In security-sensitive tooling, overstated security properties materially increase risk because operators may expose cookies, credentials, and browsing state to automation they would otherwise avoid.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill markets itself as 'secure' and suitable for sensitive/compliance use while documenting capabilities such as reusing real Chrome profiles, closing running Chrome instances, daemonized session reuse, credential discovery, and optional audit webhooks. That creates a dangerous trust mismatch: users may run it against personal or regulated accounts under the assumption of strong safeguards that are only described, not evidenced here. In security-sensitive tooling, overstated security properties materially increase risk because operators may expose cookies, credentials, and browsing state to automation they would otherwise avoid.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill markets itself as 'secure' and suitable for sensitive/compliance use while documenting capabilities such as reusing real Chrome profiles, closing running Chrome instances, daemonized session reuse, credential discovery, and optional audit webhooks. That creates a dangerous trust mismatch: users may run it against personal or regulated accounts under the assumption of strong safeguards that are only described, not evidenced here. In security-sensitive tooling, overstated security properties materially increase risk because operators may expose cookies, credentials, and browsing state to automation they would otherwise avoid.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill markets itself as 'secure' and suitable for sensitive/compliance use while documenting capabilities such as reusing real Chrome profiles, closing running Chrome instances, daemonized session reuse, credential discovery, and optional audit webhooks. That creates a dangerous trust mismatch: users may run it against personal or regulated accounts under the assumption of strong safeguards that are only described, not evidenced here. In security-sensitive tooling, overstated security properties materially increase risk because operators may expose cookies, credentials, and browsing state to automation they would otherwise avoid.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill markets itself as 'secure' and suitable for sensitive/compliance use while documenting capabilities such as reusing real Chrome profiles, closing running Chrome instances, daemonized session reuse, credential discovery, and optional audit webhooks. That creates a dangerous trust mismatch: users may run it against personal or regulated accounts under the assumption of strong safeguards that are only described, not evidenced here. In security-sensitive tooling, overstated security properties materially increase risk because operators may expose cookies, credentials, and browsing state to automation they would otherwise avoid.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill markets itself as 'secure' and suitable for sensitive/compliance use while documenting capabilities such as reusing real Chrome profiles, closing running Chrome instances, daemonized session reuse, credential discovery, and optional audit webhooks. That creates a dangerous trust mismatch: users may run it against personal or regulated accounts under the assumption of strong safeguards that are only described, not evidenced here. In security-sensitive tooling, overstated security properties materially increase risk because operators may expose cookies, credentials, and browsing state to automation they would otherwise avoid.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill markets itself as 'secure' and suitable for sensitive/compliance use while documenting capabilities such as reusing real Chrome profiles, closing running Chrome instances, daemonized session reuse, credential discovery, and optional audit webhooks. That creates a dangerous trust mismatch: users may run it against personal or regulated accounts under the assumption of strong safeguards that are only described, not evidenced here. In security-sensitive tooling, overstated security properties materially increase risk because operators may expose cookies, credentials, and browsing state to automation they would otherwise avoid.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill markets itself as 'secure' and suitable for sensitive/compliance use while documenting capabilities such as reusing real Chrome profiles, closing running Chrome instances, daemonized session reuse, credential discovery, and optional audit webhooks. That creates a dangerous trust mismatch: users may run it against personal or regulated accounts under the assumption of strong safeguards that are only described, not evidenced here. In security-sensitive tooling, overstated security properties materially increase risk because operators may expose cookies, credentials, and browsing state to automation they would otherwise avoid.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill markets itself as 'secure' and suitable for sensitive/compliance use while documenting capabilities such as reusing real Chrome profiles, closing running Chrome instances, daemonized session reuse, credential discovery, and optional audit webhooks. That creates a dangerous trust mismatch: users may run it against personal or regulated accounts under the assumption of strong safeguards that are only described, not evidenced here. In security-sensitive tooling, overstated security properties materially increase risk because operators may expose cookies, credentials, and browsing state to automation they would otherwise avoid.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill markets itself as 'secure' and suitable for sensitive/compliance use while documenting capabilities such as reusing real Chrome profiles, closing running Chrome instances, daemonized session reuse, credential discovery, and optional audit webhooks. That creates a dangerous trust mismatch: users may run it against personal or regulated accounts under the assumption of strong safeguards that are only described, not evidenced here. In security-sensitive tooling, overstated security properties materially increase risk because operators may expose cookies, credentials, and browsing state to automation they would otherwise avoid.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill markets itself as 'secure' and suitable for sensitive/compliance use while documenting capabilities such as reusing real Chrome profiles, closing running Chrome instances, daemonized session reuse, credential discovery, and optional audit webhooks. That creates a dangerous trust mismatch: users may run it against personal or regulated accounts under the assumption of strong safeguards that are only described, not evidenced here. In security-sensitive tooling, overstated security properties materially increase risk because operators may expose cookies, credentials, and browsing state to automation they would otherwise avoid.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill markets itself as 'secure' and suitable for sensitive/compliance use while documenting capabilities such as reusing real Chrome profiles, closing running Chrome instances, daemonized session reuse, credential discovery, and optional audit webhooks. That creates a dangerous trust mismatch: users may run it against personal or regulated accounts under the assumption of strong safeguards that are only described, not evidenced here. In security-sensitive tooling, overstated security properties materially increase risk because operators may expose cookies, credentials, and browsing state to automation they would otherwise avoid.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill markets itself as 'secure' and suitable for sensitive/compliance use while documenting capabilities such as reusing real Chrome profiles, closing running Chrome instances, daemonized session reuse, credential discovery, and optional audit webhooks. That creates a dangerous trust mismatch: users may run it against personal or regulated accounts under the assumption of strong safeguards that are only described, not evidenced here. In security-sensitive tooling, overstated security properties materially increase risk because operators may expose cookies, credentials, and browsing state to automation they would otherwise avoid.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill markets itself as 'secure' and suitable for sensitive/compliance use while documenting capabilities such as reusing real Chrome profiles, closing running Chrome instances, daemonized session reuse, credential discovery, and optional audit webhooks. That creates a dangerous trust mismatch: users may run it against personal or regulated accounts under the assumption of strong safeguards that are only described, not evidenced here. In security-sensitive tooling, overstated security properties materially increase risk because operators may expose cookies, credentials, and browsing state to automation they would otherwise avoid.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec, suspicious.dynamic_code_execution, suspicious.exposed_secret_literal

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
dist/browser/daemon.js:150

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
dist/browser/secure-session.js:40

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
dist/cli.js:317

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
dist/vault/discovery.js:35

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
dist/vault/index.js:12

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/onboarding.js:40

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
src/browser/daemon.ts:193

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
src/browser/secure-session.ts:66

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
src/cli.ts:372

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
src/vault/discovery.ts:71

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
src/vault/index.ts:30

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
dist/browser/secure-session.js:632

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
src/browser/secure-session.ts:747

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
dist/research/site-profiler.js:29

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
dist/vault/discovery.js:229

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
dist/vault/index.js:47

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
src/research/site-profiler.ts:55

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
src/vault/discovery.ts:308

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
src/vault/index.ts:66