Back to skill

Security audit

Clone Anywebsite

Security checks for vulnerabilities and agentic risk

Overview

This website-cloning skill needs review because it tells agents to capture exact third-party assets, shader code, and rendered canvas output despite permission warnings.

Install only with caution and use it only on sites and assets you own or have explicit permission to reproduce. As written, the skill normalizes exact copying of third-party media and browser-rendered internals; remove or ignore the shader interception, canvas recording, direct asset reuse, and broad pkill instructions before using it in normal agent workflows.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:263
Finding

Overbroad Process Termination Can Disrupt Unrelated Browser Automation Sessions

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:263
Vulnerability Type: Overbroad process termination
Risk Level: Medium

Complete Code Snippet:

markdown
- **Zombie Browsers:** If the DevTools server fails with a lock error, run `pkill -f "chrome-devtools-mcp" || true`.

Technical Analysis

The Skill recommends using pkill -f, which matches the supplied pattern against complete process command lines and terminates every accessible matching process. It does not verify that a process owns the relevant lock, belongs to the current Skill invocation, or is actually stale.

This violates least-scope process-management practices. A lock problem affecting one browser profile does not require terminating all chrome-devtools-mcp instances owned by the executing user. The appended || true also suppresses failure status, potentially concealing an unsuccessful or partially successful cleanup operation.

The behavior is local and does not provide evidence of privilege escalation beyond the permissions already held by the Agent. Nevertheless, it can terminate unrelated processes within that existing user context.

Attack Path

  1. A Chrome DevTools MCP operation reports a lock error, whether from a genuinely stale process or an active concurrent session.
  2. The Agent follows the troubleshooting instruction in SKILL.md.
  3. pkill -f enumerates processes whose complete command lines contain chrome-devtools-mcp.
  4. Every matching process that the Agent's operating-system identity is permitted to signal is terminated.
  5. Unrelated browser-automation sessions are interrupted, and their transient or unsaved state may be lost.
  6. Because || true forces a successful shell status, the workflow may continue without accurately reporting cleanup failures.

Impact Assessment

The impact is limited to processes the executing identity is already authorized to signal; this command does not itself acquire ...[truncated 584 chars]

Remediation
View remediation

Remediation Suggestions

Replace the global command-line-pattern kill with narrowly scoped cleanup:

  1. Determine the exact browser profile or lock file involved in the reported error.
  2. Resolve the PID associated with that specific lock or the process started by the current Skill invocation.
  3. Validate the PID's owner, full command line, start time, and relationship to the current task before signaling it.
  4. Ask for explicit user confirmation before terminating a process not launched by the current invocation.
  5. Send SIGTERM to the validated PID and allow a bounded grace period before considering SIGKILL.
  6. Check and report the termination result instead of masking every error with || true.
  7. Prefer graceful shutdown through the MCP server's lifecycle API when such an API is available.
  8. If no ownership-safe process identification is possible, instruct the user to inspect active sessions manually rather than executing a broad pkill -f command.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The ethical/legal notice is undermined by later instructions that advocate ripping exact assets, proprietary copy-adjacent elements, and hidden implementation details. This mismatch increases risk because it gives users apparent compliance cover while operationally guiding them toward unauthorized extraction.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill frames itself as rights-respecting, but the operative instructions explicitly direct users to 'steal' exact assets, implementation details, and rendering outputs from target sites. That contradiction makes the workflow dangerous because it facilitates unauthorized copying of proprietary media, styling, and code-adjacent artifacts under a thin legal disclaimer.

Content

No source excerpt is available for this finding.

Ssd 4

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The workflow starts with innocuous visual analysis but rapidly escalates into directions for extracting exact assets and internals from target sites, normalizing unauthorized copying as part of a standard recipe. That progression is dangerous because it lowers user resistance and operationalizes misuse under a polished productivity narrative.

Content

No source excerpt is available for this finding.

Ssd 2

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The guide uses euphemistic language such as 'deep interrogation,' 'secret sauce,' and 'steal the exact asset' to package theft-oriented behavior as standard design work. This is dangerous because it explicitly teaches users how to extract hidden assets, DOM substructures, and rendering artifacts from third-party sites while obscuring the severity behind polished terminology.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The shader interception and canvas recording sections go beyond visual analysis and provide concrete techniques to capture proprietary rendering logic or record GPU-rendered output for reuse. In this skill context, these capabilities materially enable exfiltration of non-obvious site internals and copyrighted visual assets, not just benign inspection.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The canvas recording workflow explicitly triggers a download to disk without a clear user-consent checkpoint or warning about file creation. In an agent skill, silent or under-signaled local writes are dangerous because they can surprise users, create storage artifacts, and normalize unauthorized capture of site content.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The recommendation to run a broad process-kill command is unrelated to the core cloning objective and encourages potentially unsafe shell execution on the user's machine. It can terminate unintended processes matching the pattern and normalizes destructive troubleshooting without adequate safeguards.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The screenshot-stitching command writes a combined image to disk but does not clearly call out that local files will be created and overwritten at specified paths. While comparatively low risk, this is still unsafe operational guidance for an agent because it conditions file writes without explicit confirmation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.