Back to skill

Security audit

open-deepseek

Security checks for vulnerabilities and agentic risk

Overview

This skill does what it claims: it opens Brave to DeepSeek, with no evidence of hidden data access, persistence, or destructive behavior.

Install only if you are comfortable with a skill that can launch Brave locally. Prefer a version that uses Python's webbrowser module or otherwise avoids shell=True on Windows and declares a narrow permission scope.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (6)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

This duplicate finding points to the same unsafe behavior: spawning a shell to run a browser-opening command. The current hardcoded URL reduces immediate exploitability, but the shell-enabled invocation remains a true weakness because it normalizes an unsafe pattern in an agent skill that executes host commands.

Content

Scanner excerpt · scripts/open_deepseek.py (reported line 22)May include surrounding context.

python
try:
        if computer_type == "Windows":
            # WINDOWS CAVEMAN WAY
            subprocess.Popen(["start", "brave", url], shell=True)
            
        elif computer_type == "Darwin":
            # MAC CAVEMAN WAY

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

This duplicate finding points to the same unsafe behavior: spawning a shell to run a browser-opening command. The current hardcoded URL reduces immediate exploitability, but the shell-enabled invocation remains a true weakness because it normalizes an unsafe pattern in an agent skill that executes host commands.

Content

Scanner excerpt · scripts/open_deepseek.py (reported line 22)May include surrounding context.

python
try:
        if computer_type == "Windows":
            # WINDOWS CAVEMAN WAY
            subprocess.Popen(["start", "brave", url], shell=True)
            
        elif computer_type == "Darwin":
            # MAC CAVEMAN WAY

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding

The skill invokes a script (scripts/open_deepseek.py) but does not declare any explicit tool scope such as permissions or allowed-tools. That creates an authorization gap: the runtime may permit broader file or shell capabilities than the skill description suggests, making it harder to constrain or audit what the script can do if modified or abused.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
93% confidence
Finding

This Windows branch launches a subprocess with shell=True, which invokes the system shell unnecessarily. Even though the URL is hardcoded and there is no obvious user-controlled input here, using shell=True increases attack surface and can enable command execution issues if the command or environment is influenced.

Content

Scanner excerpt · scripts/open_deepseek.py (reported line 22)May include surrounding context.

python
try:
        if computer_type == "Windows":
            # WINDOWS CAVEMAN WAY
            subprocess.Popen(["start", "brave", url], shell=True)
            
        elif computer_type == "Darwin":
            # MAC CAVEMAN WAY

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/open_deepseek.py (reported line 26)May include surrounding context.

python
elif computer_type == "Darwin":
            # MAC CAVEMAN WAY
            subprocess.Popen(["open", "-a", "Brave Browser", url])
            
        else:
            # LINUX CAVEMAN WAY

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/open_deepseek.py (reported line 30)May include surrounding context.

python
else:
            # LINUX CAVEMAN WAY
            subprocess.Popen(["brave-browser", url])
            
        print("✅ DeepSeek opening in Brave...")
        print("💬 Browser is ready! Type your prompt.")

Static analysis

No suspicious patterns detected.