Back to skill

Security audit

open-grok

Security checks for vulnerabilities and agentic risk

Overview

This skill does what it says: it opens Grok in Brave, with some minor safety and consent caveats but no evidence of hidden or malicious behavior.

Install only if you want a voice/shortcut-style command that opens Brave to Grok. Be aware it connects to an external xAI service and may use your existing browser session or prompt you to log in; the publisher should tighten trigger phrases and replace the Windows shell=True launch path with a safer browser-opening call.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (8)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
94% confidence
Finding

This duplicate finding identifies the same underlying weakness: launching via shell=True unnecessarily exposes the call to shell semantics and executable resolution issues. Even with a fixed URL, this is a genuine unsafe pattern because an attacker controlling the environment or a later code change introducing variable input could abuse the launch behavior.

Content

Scanner excerpt · scripts/open_grok.py (reported line 9)May include surrounding context.

python
system = platform.system()

if system == "Windows":
    subprocess.Popen(["start", "brave", url], shell=True)
elif system == "Darwin":
    subprocess.Popen(["open", "-a", "Brave Browser", url])
else:

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
94% confidence
Finding

This duplicate finding identifies the same underlying weakness: launching via shell=True unnecessarily exposes the call to shell semantics and executable resolution issues. Even with a fixed URL, this is a genuine unsafe pattern because an attacker controlling the environment or a later code change introducing variable input could abuse the launch behavior.

Content

Scanner excerpt · scripts/open_grok.py (reported line 9)May include surrounding context.

python
system = platform.system()

if system == "Windows":
    subprocess.Popen(["start", "brave", url], shell=True)
elif system == "Darwin":
    subprocess.Popen(["open", "-a", "Brave Browser", url])
else:

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
82% confidence
Finding

The skill appears to invoke browser-launching commands across operating systems, which implies shell/code execution capability, yet it declares no tool scope or permissions. Missing explicit scope weakens reviewability and policy enforcement because an agent may be allowed to execute commands without clear user-visible authorization boundaries.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Several triggers are broad enough to cause accidental activation, especially phrases like "start grok," "grok please," or "open xai." Unintended invocation can launch a browser and connect the user to an external service without deliberate intent, which is a meaningful safety and privacy issue in voice-activated systems.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
93% confidence
Finding

The Windows branch launches a subprocess with shell=True, which is riskier than necessary because it invokes the shell and can enable command/argument interpretation issues. In this specific file the URL is hardcoded, so immediate exploitability is limited, but using the shell for a browser launch is still an unsafe pattern that can become dangerous if any parameter later becomes user-controlled or if command resolution is hijacked.

Content

Scanner excerpt · scripts/open_grok.py (reported line 9)May include surrounding context.

python
system = platform.system()

if system == "Windows":
    subprocess.Popen(["start", "brave", url], shell=True)
elif system == "Darwin":
    subprocess.Popen(["open", "-a", "Brave Browser", url])
else:

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/open_grok.py (reported line 11)May include surrounding context.

python
if system == "Windows":
    subprocess.Popen(["start", "brave", url], shell=True)
elif system == "Darwin":
    subprocess.Popen(["open", "-a", "Brave Browser", url])
else:
    subprocess.Popen(["brave-browser", url])

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/open_grok.py (reported line 13)May include surrounding context.

python
elif system == "Darwin":
    subprocess.Popen(["open", "-a", "Brave Browser", url])
else:
    subprocess.Popen(["brave-browser", url])

print("✅ Grok opening in Brave!")

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill description and usage flow do not prominently warn that invocation will open a browser, connect to a third-party service, and may require login/subscription. That omission reduces informed user consent and may surprise users with network access, account prompts, or exposure to an external platform.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.