T05 · Unauthorized Access and Privilege Escalation
- Location
README.md:8- Finding
Documented Direct Invocation Bypasses the Launcher's Security Controls
- Content
View full analysis
Vulnerability Details
File Location:
README.md:8-23
Vulnerability Type: Authorization and integrity-control bypass
Risk Level: HighThe primary usage documentation directs users and AI agents to invoke the third-party
bwsexecutable directly instead of invokingscripts/run.js. Direct invocation bypasses all security controls implemented by the launcher.Complete vulnerable code snippet:
bash # Install npm install -g browser-web-search@0.4.3 # View all commands bws site list # Search examples bws site toutiao/search "ai search" # Toutiao bws site zhihu/search "ai agent" --count 5 # Zhihu bws site hn/search "llm" --sort date # Hacker News bws site github/search "ai search" --sort stars # GitHub bws site youtube/search "ai agent" # YouTube # jq filtering bws site zhihu/search "ai" --jq '[.items[].url]'Equivalent direct-invocation examples also appear in
SKILL.md:218-235,SKILL.md:426-427,SKILL.md:649-659, andSKILL.md:691-693.Technical Analysis
The repository implements its security boundary in
scripts/run.js. That launcher provides:- Package name, version, size, and SHA-512 verification.
- Sensitive-tier sealing.
- Per-session or per-call authorization.
- Per-platform consent bound to the verified package bytes.
- Argument allow-listing.
- Audit and transparency records.
- Symlink rejection and restricted module resolution.
None of those controls apply when the globally installed
bwsexecutable is called directly. The documentation therefore creates an alternate execution path around the intended reference monitor.This is particularly dangerous for authenticated adapters because the underlying package executes JavaScript in an OpenClaw browser session. The issue does not require defeating any launcher gate: the documented command simply avoids the launcher entirely.
Attack Path
- A user or ...[truncated 1220 chars]
- Remediation
View remediation
Remediation Suggestions
-
Replace every operational
bws site ...example with the protected launcher:bash node scripts/run.js run hn/search "llm" --count 5or with a verified
bws-skillwrapper that unconditionally resolves toscripts/run.js. -
Remove direct
bwsinvocations from:- The README quick-start section.
- SKILL installation and usage instructions.
- Example conversations.
- Login-state instructions.
- First-run checklists.
-
Clearly state that direct use of the upstream binary is unsupported because it bypasses integrity checks, consent gates, and auditing.
-
If a wrapper executable is distributed, ensure it cannot fall back to the raw upstream executable and add automated documentation tests that reject command examples beginning with
bws site. -
Consider installing the upstream dependency without exposing its executable globally. A launcher-private installation reduces the likelihood of accidental bypass.
-
