Back to skill

Security audit

auto-fill

Security checks for vulnerabilities and agentic risk

Overview

This form-filling skill is mostly aligned with its purpose, but it asks the agent to start and control a real Chrome debug session in ways that are too broad and under-scoped for automatic installation.

Install only if you are comfortable letting the skill and its MCP dependency control a Chrome debug session. Prefer a pinned, reviewed MCP package, a dedicated temporary browser profile, explicit approval before launching Chrome or navigating, and clear cleanup that closes the debug browser and removes temporary data after use.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Error
Location
SKILL.md:109
Finding

Unpinned MCP Package Is Automatically Downloaded and Executed

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:29
Finding

Persistent Unauthenticated Chrome DevTools Endpoint Is Left Running

Content
View full analysis
/tmp/chrome_debug.log 2>&1 & ``` The instructions then wait and continue after confirming that the endpoint is available, but provide no shutdown or cleanup procedure. ### Technical Analysis Chrome DevTools Protocol provides highly privileged browser control, including page inspection, navigation, JavaScript execution, screenshots, and access to form data in controlled pages. The Skill starts this interface on a fixed port and backgrounds the process with `nohup`, causing it to remain active independently of the immediate shell operation. Although the documented URL uses loopback and the isolated `/tmp/chrome_debug_profile` is safer than attaching to the user's normal Chrome profile, no application-level authentication protects the endpoint from other processes running on the same host. The fixed port also makes endpoint discovery trivial. The workflow does not record the spawned process ID, stop Chrome after form filling, remove the temporary profile, or ensure restrictive permissions on the temporary profile and log. This leaves a high-privilege browser-control surface active beyond the period needed for the declared functionality. ### Attack Path 1. The Skill finds no service on port 9222 and starts Chrome in the background with remote debugging enabled. 2. The user browses to a page or enters data in the debug-controlled browser. 3. The form-filling task ends, but the instructions do not terminate the ...[truncated 1228 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (7)

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

Launching Chrome via shell is not necessary to the core task of identifying and filling fields once a browser session is available, and it gives the skill host-level process execution behavior. That creates a meaningful boundary break: a form-filling skill should not silently gain the ability to spawn local applications, create profiles, and persist background processes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill is designed to inspect and interact with the user's real Chrome session through CDP, which can expose sensitive page contents, autofilled data, and authenticated context. The documentation does not provide a prominent privacy warning or explain that live browser data from the user's real session will be read and used.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest describes CDP-based form reading/filling, but the documentation additionally instructs the agent to use shell commands to start a local Chrome instance. This is a material capability expansion from browser automation to local process execution, which can affect the host system and user session in ways not disclosed by the skill metadata.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instructions direct the agent to execute a local process launch command immediately and in the background, without a clear user-facing warning or consent checkpoint. Even if the command only starts Chrome, undisclosed local execution is risky because it changes system state, opens a debug port, and may expose the user's authenticated browser context.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
90% confidence
Finding

Using nohup to start Chrome in the background with a dedicated profile creates a persistent debugging-capable browser process beyond the immediate interaction. In a real-user environment, persistent debug sessions increase exposure because the remote debugging port and authenticated browser state may remain available longer than intended.

Content

Scanner excerpt · SKILL.md (reported line 40)May include surrounding context.

直接执行(后台启动):

bash
nohup /Applications/Google\ Chrome.app/Contents/MacOS/Google\ Chrome \
  --remote-debugging-port=9222 \
  --user-data-dir="/tmp/chrome_debug_profile" \
  > /tmp/chrome_debug.log 2>&1 &

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill expands its behavior from form-filling into autonomous destination inference and navigation, telling the agent to guess target URLs and browse there without requiring an explicit user-provided link. In the context of a real logged-in Chrome session, this increases the chance of unintended navigation to sensitive sites, phishing lookalikes, or user-confusing actions outside the narrow declared scope.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

All user-facing natural-language instructions in the skill are written in Chinese, with no indication that another language can be used or that the locale is intentionally constrained. This can violate language or locale policy when a skill implicitly forces a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.