T09 · Insecure Skill Coding Practices
- Location
scraper.js:219- Finding
Unrestricted URL Navigation Enables Server-Side Request Forgery
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This scraper largely does what it advertises, but it needs review because it can browse arbitrary targets with weakened browser protections and can expose its license key in output.
Install only if you are comfortable running a commercial stealth-scraping browser tool in an isolated environment. Do not use it on sites or data you are not authorized to scrape, avoid authenticated or internal URLs, treat the license key as a secret, and prefer a sandboxed container or VM with restricted outbound network access.
scraper.js:219Unrestricted URL Navigation Enables Server-Side Request Forgery
scraper.js:71TLS Verification and Chromium Sandbox Protections Are Disabled
scraper.js:308License Credential Is Disclosed in Plaintext Output
The documented purpose emphasizes scraping, but the skill also includes license validation/gating and filesystem output behaviors that are not clearly declared as operational capabilities. This mismatch reduces transparency for users and agent frameworks, making it easier to hide consequential behaviors or obtain consent under incomplete disclosure.
The skill declares an environment-variable dependency but does not define an explicit tool scope or permissions boundary. In agent environments, missing scope declarations can cause users or orchestrators to grant broader access than intended, especially when the skill also performs browser automation and local file output.
The skill promotes stealth scraping and anti-bot bypass without warning users about privacy, legal, terms-of-service, or system-integrity implications. Because the context is specifically anti-detection web automation, omission of safety warnings makes misuse more likely and increases the risk of abusive or non-compliant deployment.
Using 'npx playwright' without a pinned version allows execution of whatever package version resolves at install time, creating a supply-chain risk. A compromised or breaking upstream release could introduce malicious code or unsafe behavior into the skill setup path.
The activation prompt is broad and lacks boundaries on when the agent should invoke scraping behavior, which can lead to unintended autonomous use on arbitrary URLs or sensitive targets. In an agent setting, underspecified triggers increase the chance of overreach, privacy issues, or actions that violate site policies.
The manifest describes a web-scraping capability, but the code additionally depends on reading a local secret from process.env for license enforcement. Accessing environment-held credentials is not an obvious requirement of scraping itself and expands the skill's access to host-side sensitive data.
The browser context is hard-coded to use en-US, America/New_York, and a fixed New York geolocation. This imposes a specific language/locale profile on all users without offering choice or documenting a justified regional constraint.
The validate command prints the full license key to the console, which exposes sensitive secret material to terminal history, logs, screenshots, CI output, and shell session recording tools. Although the secret is a product license rather than a cloud credential, it is still a reusable token that can be copied and abused by others.
Printing the license key without warning creates an avoidable secret disclosure path and increases the chance that users leak credentials unintentionally into logs or support transcripts. The skill context does not require displaying the secret for scraping functionality, so this exposure is unjustified.
The dependency is version-ranged with a caret, so future installs may pull newer minor/patch releases that were not specifically reviewed or tested. This creates supply-chain risk because a compromised or breaking upstream release could be introduced into the skill without any code change in this repository.
],
"license": "Commercial",
"dependencies": {
"playwright": "^1.58.0",
"commander": "^12.0.0"
}
}
The dependency is not strictly pinned and allows npm to resolve to later compatible releases at install time. In a scraping tool that depends on browser automation and CLI parsing, this increases supply-chain exposure and reproducibility risk if an upstream package is compromised or unexpectedly changes behavior.
"license": "Commercial",
"dependencies": {
"playwright": "^1.58.0",
"commander": "^12.0.0"
}
}
No suspicious patterns detected.