Back to skill

Security audit

Agent Browser

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent browser automation helper, but it normalizes saving reusable authenticated browser sessions without adequate safety guidance.

Review this skill before installing if you plan to use it on logged-in sites. Treat saved state files, traces, screenshots, videos, PDFs, cookies, and storage dumps like credentials or sensitive records; store them in protected locations and delete them when no longer needed.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Context Window Stuffing

Medium
Category
Memory Poisoning
Confidence
85% confidence
Finding

Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.

Content

Scanner excerpt · SKILL.md (reported line 41)May include surrounding context.

agent-browser open # Navigate to page agent-browser snapshot -i # Get interactive elements with refs agent-browser click @e1 # Click element by ref agent-browser fill @e2 "text" # Fill input by ref agent-browser close # Close browser

text

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documented commands create local artifacts such as screenshots, PDFs, videos, traces, and auth/session files, all of which may capture sensitive page contents, credentials, tokens, or PII. Without a warning, an agent may write these files to disk by default and leave recoverable sensitive data behind.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly encourages saving and loading browser session state and also exposes cookies and storage operations, but it does not warn that these artifacts can contain active authentication tokens, cookies, and other secrets. In an agent context, this can lead to inadvertent persistence, reuse, or leakage of privileged sessions across tasks, users, or machines.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
90% confidence
Finding

The skill provides a direct mechanism to save and later reload authenticated browser state, which enables session persistence across runs. In an agent environment, persisted auth state can be copied, reused outside the original context, or accidentally shared, resulting in unauthorized account access if the file is exposed.

Content

Scanner excerpt · SKILL.md (reported line 236)May include surrounding context.

bash
agent-browser state save auth.json    # Save session state
agent-browser state load auth.json    # Load saved state

Example: Form submission

Session Persistence

Medium
Category
Rogue Agent
Confidence
93% confidence
Finding

The authentication example normalizes saving login state to auth.json and reusing it later, but omits any caution that the file may contain reusable authenticated session material. This makes the pattern more dangerous because it is presented as a recommended workflow, increasing the chance of insecure operational use by agents or users.

Content

Scanner excerpt · SKILL.md (reported line 265)May include surrounding context.

agent-browser wait --url "/dashboard" agent-browser state save auth.json

Later sessions: load saved state

agent-browser state load auth.json agent-browser open https://app.example.com/dashboard

text

Static analysis

No suspicious patterns detected.