Back to skill

Security audit

Agent Browser

Security checks for vulnerabilities and agentic risk

Overview

This is a legitimate browser automation skill, but it gives agents ways to save reusable logged-in browser sessions and capture page data without enough safeguards for those sensitive artifacts.

Review before installing if you will use it on real accounts or private sites. Treat auth-state JSON files, recordings, screenshots, PDFs, extracted page text, uploaded files, cookies, storage values, and proxy URLs as sensitive. Store saved browser state outside repositories in private directories with owner-only permissions, avoid persisting post-2FA sessions when possible, use test accounts and synthetic data for recordings, and delete or revoke saved sessions after use.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
templates/authenticated-session.sh:15
Finding

Authentication State Files Are Saved Without Explicit Access Controls

Content
View full analysis
Remediation
View remediation
&2 exit 1 fi install -m 600 /dev/null "$STATE_FILE" agent-browser state save "$STATE_FILE" chmod 600 -- "$STATE_FILE" ``` 3. For temporary state, use a private runtime directory and an unpredictable filename rather than a fixed `/tmp` path: ```bash umask 077 STATE_FILE="$(mktemp "${XDG_RUNTIME_DIR:-/tmp}/agent-browser-state.XXXXXX.json")" trap 'rm -f -- "$STATE_FILE"' EXIT ``` 4. Verify that the selected path is a regular file owned by the current user before loading it: ```bash if [[ ! -f "$STATE_FILE" || -L "$STATE_FILE" || ! -O "$STATE_FILE" ]]; then echo "ERROR: Unsafe authentication state file" >&2 exit 1 fi ``` 5. Delete state files as soon as reuse is no longer required and revoke the associated web session after suspected disclosure. 6. Update every documentation example to use environment-provided credentials, private state directories, restrictive permissions, and automatic cleanup. Retain the existing recommendation to exclude all state files from version control, but do not treat `.gitignore` as an access-control mechanism. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (16)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The documentation instructs users to save authentication state to disk and reload it later without warning that the file may contain reusable session tokens, cookies, and other secrets. If that file is copied, committed, or read by another user or process, an attacker may hijack authenticated sessions without needing credentials.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/authentication.md (reported line 179)May include surrounding context.

  1. Clean up after automation

    bash
    agent-browser cookies clear
    rm -f ./auth-state.json
    
  2. Use short-lived sessions for CI/CD

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/session-management.md (reported line 173)May include surrounding context.

echo "*.auth-state.json" >> .gitignore

Delete after use

rm /tmp/auth-state.json

text

### 4. Timeout Long Sessions

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly supports form filling, screenshots, PDFs, video capture, cookies, storage, and data extraction, but provides no privacy or sensitive-data handling guidance. In a browser automation skill, this omission increases the likelihood that operators will capture credentials, personal data, or proprietary content and persist it insecurely.

Content

No source excerpt is available for this finding.

Context Window Stuffing

Medium
Category
Memory Poisoning
Confidence
85% confidence
Finding

Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.

Content

Scanner excerpt · SKILL.md (reported line 15)May include surrounding context.

agent-browser open # Navigate to page agent-browser snapshot -i # Get interactive elements with refs agent-browser click @e1 # Click element by ref agent-browser fill @e2 "text" # Fill input by ref agent-browser close # Close browser

text

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The recording feature preserves cookies and storage into a fresh context and encourages recording workflows, but does not warn that the resulting video may expose account data, internal pages, tokens visible in the UI, or other sensitive information. Because recordings are durable artifacts, accidental sharing can turn transient exposure into persistent leakage.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
97% confidence
Finding

Persisting and reloading browser session state enables reuse of authenticated sessions across runs, which is useful operationally but also creates a credential-equivalent artifact. In this skill's context, the danger is elevated because the browser tool also supports cookies, storage inspection, and authenticated automation, making session theft or unintended privilege reuse more likely if state files are exposed.

Content

Scanner excerpt · SKILL.md (reported line 283)May include surrounding context.

agent-browser wait --url "**/dashboard" agent-browser state save auth.json

Later sessions: load saved state

agent-browser state load auth.json agent-browser open https://app.example.com/dashboard

text

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The example instructs users to save authenticated browser state to disk immediately after login, and that state commonly contains reusable session cookies or tokens. Although the document later mentions not committing state files, the example itself lacks an inline warning at the point of use, which increases the chance that users will store active credentials insecurely and accidentally reuse, share, or commit them.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Saving browser state after an OAuth/SSO flow is especially sensitive because the file may capture active first-party session cookies and tokens established after federated login. Without an immediate warning, users may underestimate the sensitivity of oauth-state.json, leading to token leakage through source control, logs, shared workspaces, or artifact retention.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Persisting browser state after successful 2FA is more dangerous than a normal login example because the resulting file may effectively bypass a second authentication factor for the lifetime of the session. If that file is exposed, an attacker may gain authenticated access without needing the user’s password and second factor again.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation explicitly demonstrates embedding proxy usernames and passwords directly in environment-variable URLs. While common in examples, this is risky because such credentials can be exposed through shell history, process listings, logs, CI output, or copied scripts, leading to proxy account compromise or unintended lateral access through trusted network paths.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
55% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/session-management.md (reported line 43)May include surrounding context.

Load Session State

bash
# Restore saved state
agent-browser state load /path/to/auth-state.json

# Continue with authenticated session

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation encourages recording browser sessions and saving artifacts but omits any warning that videos and screenshots can capture sensitive information such as credentials, personal data, session details, and internal application content. In a browser automation skill, users are likely to run flows against real sites and environments, so this omission can lead to inadvertent data retention and leakage through saved files or CI artifacts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The login recording example shows entering an email and password while recording the session, but it does not warn that the resulting video artifact will preserve those interactions and potentially expose credentials or other account data. Because this example is likely to be copied into documentation, testing, or CI workflows, it materially increases the chance of secret disclosure through stored recordings.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The template includes a concrete file upload command that would transmit a local file to whatever remote form the operator is automating, but it provides no warning, confirmation step, or guidance about data sensitivity. In a browser-automation skill, this is materially risky because users may adapt the example verbatim and unintentionally upload sensitive local documents to untrusted sites.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

This section demonstrates iterating through multiple URLs with rotating proxies and saving extracted body text to output-$i.txt. The description does not disclose that it performs automated scraping and persists retrieved data locally, which can affect user data handling and compliance expectations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.