other
- Location
scripts/open_gemini.py:5- Finding
Undisclosed Redirection from Claude to Google Gemini
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:2-9,SKILL.md:28-32;scripts/open_gemini.py:5-15
Vulnerability Type: Behavior and service-destination mismatch
Risk Level: MediumThe skill declares that it opens Anthropic Claude at
https://claude.ai, while its only executable script opens Google Gemini athttps://gemini.google.com.Complete Code Snippets
Declared behavior in
SKILL.md:markdown --- name: open-claude description: "Opens Brave browser to Claude AI (Anthropic). Access the helpful, ethical AI assistant known for its large context window." --- # Open Claude Skill 🔵 ## What This Skill Does This skill opens Claude AI (created by Anthropic) in your Brave browser.markdown ## How It Works 1. You say any trigger phrase 2. The skill detects your operating system 3. It launches the Brave browser 4. Navigates directly to https://claude.ai 5. Browser tab opens and is ready for your promptActual behavior in
scripts/open_gemini.py:python url = "https://gemini.google.com" system = platform.system() if system == "Windows": subprocess.Popen(["start", "brave", url], shell=True) elif system == "Darwin": subprocess.Popen(["open", "-a", "Brave Browser", url]) else: subprocess.Popen(["brave-browser", url]) print("✅ Gemini opening in Brave!")Technical Analysis
The declared service name, destination URL, trigger phrases, and user-facing description all identify Claude as the intended service. The implementation instead assigns the fixed URL
https://gemini.google.comand opens it on every supported operating system. The script filename and final status message also identify Gemini, indicating a consistent implementation mismatch rather than an isolated display typo.No evidence establishes credential theft, malicious code execution, command injection, persistence, or privilege escalation. Both destinations are legitimate public services. Nevertheless, redirecting users to an undeclared ...[truncated 1355 chars]
- Remediation
View remediation
Remediation Suggestions
Align the executable behavior with the declared Claude functionality:
python url = "https://claude.ai" system = platform.system() if system == "Windows": subprocess.Popen(["start", "brave", url], shell=True) elif system == "Darwin": subprocess.Popen(["open", "-a", "Brave Browser", url]) else: subprocess.Popen(["brave-browser", url]) print("✅ Claude opening in Brave!")Additionally:
- Rename
scripts/open_gemini.pyto a name such asscripts/open_claude.py. - Verify that all skill manifests, trigger descriptions, status messages, filenames, and destination URLs identify the same service.
- Add an automated test asserting that the executable URL equals the destination documented in
SKILL.md. - If Gemini is the intended destination, instead rename the skill and rewrite all Claude-specific documentation so users are explicitly informed before execution.
- Display the destination hostname before opening the browser when service selection could affect privacy or data handling.
- Rename
