Back to skill

Security audit

Browser Demo Recorder

Security checks for vulnerabilities and agentic risk

Overview

This browser recording skill is coherent for making demo videos, but it needs review because its plans can run arbitrary page JavaScript, choose unvalidated browser endpoints and output paths, and persist typed text in debug logs.

Install only if you are comfortable with a browser automation skill that can control and record pages. Use it with a dedicated, non-authenticated browser profile, avoid entering passwords or tokens in recording plans, do not run plans from untrusted sources, and keep outputs inside the workspace media directory until the runner enforces those limits.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/run-recording.mjs:175
Finding

Arbitrary JavaScript Execution in the Active Browser Page

Content
View full analysis
{ const fn = new Function(`return (${code});`)(); return fn(args || {}); }, { code: step.code, args: step.args || {} } ); if (step.holdMs) await page.waitForTimeout(step.holdMs); return { browser, page, interactionLog }; } ``` ### Technical Analysis The runner reads a JSON plan and accepts an `evaluate` step whose `code` property is compiled using `new Function`. No schema enforcement, operation allowlist, origin restriction, integrity check, or trust validation is applied before the code executes through Puppeteer in the active page. The dynamically supplied function runs in the context of the currently loaded web page. It can access DOM content and browser-accessible application state, perform arbitrary page interactions, and initiate network requests permitted by the page's execution environment. If the connected browser contains authenticated sessions, the code may operate with those existing session privileges. The code is also copied into the interaction log, but logging does not mitigate its execution. ### Attack Path 1. An attacker supplies or modifies a recording plan. 2. The plan includes an `evaluate` step with malicious JavaScript in `step.code`. 3. The runner parses the plan without validating the code. 4. `new Function` compiles the supplied expression. 5. `page.evaluate` executes it in the active browser page. 6. The payload reads sensitive page data or performs actions using the page's authenticated session. 7. The payload can transmit accessible information through requests initiated from the page, subject to browser security controls. ### Impact Assessment Successful exp ...[truncated 473 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/run-recording.mjs:363
Finding

Unrestricted Plan-Controlled CDP Endpoint

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/run-recording.mjs:48
Finding

Plan-Controlled Output Directory Allows Writes Outside the Workspace

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/run-recording.mjs:252
Finding

Sensitive Typed Values Are Persisted in Plaintext Debug Logs

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Rogue AgentSelf-Modification, Session Persistence
Findings (12)

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · SKILL.md (reported line 53)May include surrounding context.

md
- Writes both MP4 and debug JSON into the plan's `outputDir`
- Default output directory should be the current workspace `media/` directory

## Output Rules

Always set the plan `outputDir` to the workspace media directory unless the user explicitly asks for a different safe location.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The evaluate step executes attacker-controlled JavaScript from the plan via new Function(...) inside the visited page. For a browser demo recorder, this materially expands capability beyond navigation/recording and enables arbitrary DOM/script actions on any page the browser can access, including authenticated sessions, making abuse much more dangerous in this skill context.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The arbitrary code execution capability is real and unjustified for the advertised purpose of recording browser demos. Because the plan can inject custom JavaScript into any visited page, the skill can be repurposed to manipulate page state, access sensitive in-page data, or perform actions hidden behind normal UI constraints.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

Line L03 says to use the skill when the user wants a 'browser walkthrough, product demo, site recording, landing-page capture, hover/click/search flow recording,' which is a wide set of loosely bounded triggers without exclusions or negative examples. This ambiguity could cause unintended invocation for ordinary browsing-help or demo-related requests that do not clearly ask for video recording.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Line L65 provides the success response example entirely in Chinese ('录好了,时长约 42 秒。') with no indication that language should follow user preference. This can violate language or locale policy by implicitly steering output to a specific language without opt-in.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/example-skills-video-plan.json (reported line 162)May include surrounding context.

json
},
      "steps": 28,
      "holdMs": 3600,
      "note": "Hover near create entry for ending"
    }
  ]
}

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The module connects to a Chrome DevTools Protocol endpoint taken from an environment variable and falls back to a localhost URL, with no validation, allowlist, authentication expectations, or user disclosure. If an attacker can influence OPENCLAW_CDP_URL or the runtime environment, the skill could attach to an unintended browser instance and gain powerful control over pages, cookies, session state, and network activity.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

buildPaths resolves plan.meta.outputDir directly and writes output there, allowing a plan author to redirect video/debug artifacts outside the intended workspace media/ directory. In an agent setting this can overwrite or place files in unexpected locations, violating the documented containment boundary for this skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The interaction log records step.text verbatim for typing actions, which can capture credentials, API keys, search queries, or other sensitive user input into a persistent debug JSON file. In a browser automation skill, this is especially risky because typed data often includes secrets entered into authenticated sites.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The script starts a recorder and writes both a video file and a detailed debug JSON file of the session, which may contain user data, visited URLs, and page interaction details. There is no confirmation prompt or descriptive comment/docstring warning the operator in advance that a full recording and debug artifact will be created.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The markdown explains that output lands in the workspace media/ directory, but it does not present this as a user-facing warning about filesystem modification or retention of artifacts. Because the skill creates files and may also save debug JSON, a clearer disclosure would better inform users about data and workspace impact.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
91% confidence
Finding

The dependency version specifier uses a caret range, which allows newer minor/patch releases to be installed implicitly. This creates supply-chain risk because a future compromised or breaking release of the package could be pulled into the recording skill without deliberate review, and this skill operates in a browser-automation context where dependencies may receive sensitive page content and control browser actions.

Content

Scanner excerpt · package.json (reported line 11)May include surrounding context.

json
},
  "dependencies": {
    "puppeteer-core": "19.0.0",
    "puppeteer-screen-recorder": "^3.0.6"
  }
}

Static analysis

Detected: suspicious.dynamic_code_execution

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
scripts/run-recording.mjs:183