Back to skill

Security audit

open-chatgpt

Security checks for vulnerabilities and agentic risk

Overview

This skill is a simple browser launcher for ChatGPT and its behavior matches its stated purpose, though its Windows launch command could be implemented more safely.

Install only if you are comfortable with the skill launching Brave locally. The Windows implementation should ideally avoid shell=True, but the current artifact uses a fixed ChatGPT URL and shows no hidden data access, persistence, or destructive behavior.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (6)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

This duplicate finding refers to the same Windows shell-backed process launch. While the current inputs are static, the pattern is still unsafe by design because shell interpretation is unnecessary and increases the risk of command or parameter abuse.

Content

Scanner excerpt · scripts/open_chatgpt.py (reported line 9)May include surrounding context.

python
system = platform.system()

if system == "Windows":
    subprocess.Popen(["start", "brave", url], shell=True)
elif system == "Darwin":
    subprocess.Popen(["open", "-a", "Brave Browser", url])
else:

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

This duplicate finding refers to the same Windows shell-backed process launch. While the current inputs are static, the pattern is still unsafe by design because shell interpretation is unnecessary and increases the risk of command or parameter abuse.

Content

Scanner excerpt · scripts/open_chatgpt.py (reported line 9)May include surrounding context.

python
system = platform.system()

if system == "Windows":
    subprocess.Popen(["start", "brave", url], shell=True)
elif system == "Darwin":
    subprocess.Popen(["open", "-a", "Brave Browser", url])
else:

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill description indicates it launches a browser via OS-specific commands, which implies shell/process execution capability, but the manifest does not declare any explicit tool scope such as permissions or allowed-tools. This creates a transparency and policy-enforcement gap: reviewers and runtime controls cannot easily verify or constrain what the skill is allowed to execute, increasing the risk of unintended command execution or scope creep if the implementation changes.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
88% confidence
Finding

The Windows branch invokes subprocess.Popen with shell=True, which causes execution through the command shell. Even though the URL is hardcoded here, shell invocation expands the attack surface and can enable command execution if the command components or environment are influenced unexpectedly.

Content

Scanner excerpt · scripts/open_chatgpt.py (reported line 9)May include surrounding context.

python
system = platform.system()

if system == "Windows":
    subprocess.Popen(["start", "brave", url], shell=True)
elif system == "Darwin":
    subprocess.Popen(["open", "-a", "Brave Browser", url])
else:

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/open_chatgpt.py (reported line 11)May include surrounding context.

python
if system == "Windows":
    subprocess.Popen(["start", "brave", url], shell=True)
elif system == "Darwin":
    subprocess.Popen(["open", "-a", "Brave Browser", url])
else:
    subprocess.Popen(["brave-browser", url])

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/open_chatgpt.py (reported line 13)May include surrounding context.

python
elif system == "Darwin":
    subprocess.Popen(["open", "-a", "Brave Browser", url])
else:
    subprocess.Popen(["brave-browser", url])

print("✅ ChatGPT opening in Brave!")

Static analysis

No suspicious patterns detected.