T09 · Insecure Skill Coding Practices
- Location
scripts/render_note_png.js:379- Finding
Headless Brave Runs with Browser Sandboxing Disabled
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill does what it claims, but its renderer disables important browser isolation while processing user-controlled notes, so it should be reviewed before installation.
Install only if you are comfortable with a local renderer that launches Brave with browser sandboxing disabled. Avoid rendering untrusted notes, do not run it as root, prefer an isolated low-privilege container/user, and consider removing the sandbox-disabling flags before regular use.
scripts/render_note_png.js:379Headless Brave Runs with Browser Sandboxing Disabled
The troubleshooting guide instructs operators to run Chromium/Brave with --no-sandbox and --disable-setuid-sandbox when executing as root, but it does not warn that this removes a major browser security boundary. In this skill's context, the browser renders KaTeX/HTML and opens local files with --allow-file-access-from-files, so disabling sandboxing materially increases risk if untrusted content is ever rendered or a browser bug is exploited.
The script launches Brave with --no-sandbox and --disable-setuid-sandbox while rendering untrusted, user-provided content. Even though the HTML is mostly locally generated, KaTeX output and browser parsing still process attacker-controlled input, so any browser or rendering-engine exploit would run without the normal containment layer, substantially increasing the consequence of compromise.
The top-level description uses Russian-only wording ("конспект"), and later user-facing warnings also include Russian-only text. This imposes a language choice in natural-language interactions without offering an alternative or documenting a justified locale restriction.
The preflight lint comment and related warning context include Russian-only wording ("казусы"), reinforcing a fixed locale in user-facing messaging. Under the policy, language constraints should be optional or clearly justified.
The script enables --allow-file-access-from-files, which weakens local file:// isolation and can permit a locally opened page to load other local files. In this skill, attacker-controlled note content is rendered into HTML and opened by Brave; if any HTML/script injection becomes possible through KaTeX output or a browser quirk, this flag can expand impact to local file disclosure.
Detected: suspicious.dangerous_exec