Back to skill

Security audit

企业背景调查(智访通)

Security checks for vulnerabilities and agentic risk

Overview

The skill has a coherent business-research purpose, but it needs review because it tells agents to run user-provided company names through shell commands without sanitization and recommends unpinned global tool installation.

Install only after reviewing the browser dependency source and avoiding global or elevated installation where possible. Use trusted, pinned versions, and do not run this skill on attacker-controlled company names unless the agent URL-encodes or validates the input first. Treat generated executive/contact profiles as sensitive business intelligence and use them only where public-data aggregation is lawful and appropriate.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:76
Finding

Shell Command Injection Through Unsanitized Company Name Interpolation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 76-127
Vulnerability Type: Shell command injection through unsafe interpolation of user-controlled input
Risk Level: High

Evidence

bash
# 1. Core corporate information
agent-browser open "https://www.baidu.com/s?wd={company}+参保人数+高新技术企业"
agent-browser snapshot -c

# 2. Shareholders, affiliated companies, and branches
agent-browser open "https://www.baidu.com/s?wd={company}+股东+实际控制人+分支机构"
agent-browser snapshot -c

# 3. Official website and business information
agent-browser open "https://www.baidu.com/s?wd={company}+官网"
agent-browser snapshot -c

# 4. Financing information
agent-browser open "https://www.baidu.com/s?wd={company}+融资"
agent-browser snapshot -c

# 5. Recruitment activity
agent-browser open "https://www.baidu.com/s?wd={company}+招聘+最新"
agent-browser snapshot -c

# 6. Bid awards
agent-browser open "https://www.baidu.com/s?wd={company}+中标+2024+2025"
agent-browser snapshot -c

# 7. Recent news
agent-browser open "https://so.toutiao.com/search?keyword={company}"
agent-browser snapshot -c

# 8. WeChat articles
agent-browser open "https://wx.sogou.com/weixin?type=2&query={company}"
agent-browser snapshot -c

# 9. Executive background
agent-browser open "https://www.baidu.com/s?wd={company}+创始人+董事长+经历"
agent-browser snapshot -c

# 10. Local activities
agent-browser open "https://www.baidu.com/s?wd={company}+苏州+工业园区"
agent-browser snapshot -c

# 11. Cooperation projects
agent-browser open "https://www.baidu.com/s?wd={company}+战略合作+签约"
agent-browser snapshot -c

# 12. Supplemental verification
agent-browser open "https://www.so.com/s?q={company}+核心业务+产品优势"
agent-browser snapshot -c

Technical Analysis

The {company} placeholder represents a company name supplied by the user. It is inserted directly into double-quoted shell command arguments without URL encoding, strict character va ...[truncated 1942 chars]

Remediation
View remediation

Remediation Suggestions

  1. Do not construct shell commands by inserting raw user input into command strings.
  2. Validate company names against a narrowly defined policy. Reject control characters, quotes, newlines, backticks, dollar signs, redirection characters, and shell control operators.
  3. URL-encode the company name using a fixed, trusted encoding function before constructing the search URL.
  4. Pass the command and its arguments through a direct process-spawning API that does not invoke a shell.
  5. If Bash is unavoidable, place the encoded URL in a safely quoted positional parameter rather than generating executable command text.
  6. Configure the tool authorization layer to reject compound commands, substitutions, pipes, redirections, newlines, and additional executables even when the command starts with agent-browser.
  7. Add tests using adversarial input containing quotes, semicolons, command substitutions, newlines, and URL delimiters to verify that it remains a single inert URL argument.

T08 · Insecure Dependencies

Warning
Location
SKILL.md:23
Finding

Unpinned Global Installation of a Third-Party Browser Dependency

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 23-31
Vulnerability Type: Unpinned third-party dependency installation
Risk Level: Medium

Evidence

bash
clawhub install TheSethRose/agent-browser
bash
npm install -g agent-browser && agent-browser install --with-deps

The package metadata separately identifies the browser source as:

json
"agent_browser_source": "https://github.com/vercel-labs/agent-browser"

Technical Analysis

Both installation alternatives resolve mutable package references without specifying an exact version or integrity digest. The npm command performs a global installation and then invokes the installed executable with install --with-deps, increasing the consequences of a compromised package, publisher account, registry response, or transitive dependency.

The ClawHub installation reference uses the namespace TheSethRose/agent-browser, while metadata.json identifies the upstream source as the vercel-labs/agent-browser GitHub repository. The audited files do not provide evidence tying those identities together or pinning either source to a reviewed artifact.

This is a supply-chain exposure rather than evidence that the current upstream package is malicious. The risk arises because the code installed in the future can change independently of this Skill review.

Attack Path

  1. A user runs the Skill without agent-browser installed.
  2. The Skill instructs the user to execute one of the unpinned installation commands.
  3. The package manager resolves the current package and its transitive dependencies at installation time.
  4. A compromised publisher, registry, namespace, package version, or dependency supplies hostile installation or runtime code.
  5. Package installation hooks or the subsequent agent-browser install --with-deps execution run that code with the installing user's permissions.
  6. Because the npm installation ...[truncated 721 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin agent-browser to an exact reviewed version rather than resolving the latest release.
  2. Verify the package with a cryptographic integrity digest or signed release metadata.
  3. Confirm and document the relationship between the ClawHub publisher namespace and the cited upstream GitHub organization.
  4. Prefer the verified upstream publisher and remove unverifiable claims that a registry entry has been audited.
  5. Avoid global installation where possible; install into an isolated, least-privileged environment.
  6. Lock and review transitive dependencies and installation scripts.
  7. Document the expected binary checksum and provide a verification step before first execution.
  8. Avoid elevated installation and clearly warn users not to run the package manager as root or administrator.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (5)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill metadata and instructions are written to enforce Chinese-language interaction/output without offering a language choice or documenting a locale-only requirement. This is primarily a usability and transparency issue, but it can also increase the risk of user misunderstanding about what data is being collected and how results are presented, especially for multilingual users.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly instructs collection and output of personal contact details, executive identities, backgrounds, education, hometown, and public activities from multiple public sources, but it provides no user-facing warning, consent notice, or minimization guidance. Even when sourced from public search engines, aggregating and structuring this data materially increases privacy and profiling risk, especially in a sales/customer-manager context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The config fixes all search engines to China-specific services and regions, and also hard-codes the operating region and focus area as Chinese locales. This creates a natural-language locale policy concern because the skill appears to force a specific language/region context without offering user choice or documenting why this restriction is required.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The description is written only in Chinese and explicitly states the tool is for China Telecom account managers, while the region is fixed to Suzhou. This indicates a language/locale constraint without any visible opt-in, alternative language support, or documented justification as a region-specific compliance requirement.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The natural-language content in the changelog is entirely in Chinese and includes a region-specific focus on Suzhou/Suzhou Industrial Park. For a policy review, this can indicate a language/locale constraint without any visible user opt-in or explanation that the skill is intentionally region-specific.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.