Back to skill

Security audit

Clawbrowser

Security checks for vulnerabilities and agentic risk

Overview

This browser automation skill is purpose-aligned and disclosed, but users should handle browser sessions, recordings, and the global install command carefully.

Install only from a trusted npm registry, preferably with a pinned Playwright CLI version. Use isolated sessions for sensitive sites, delete named sessions after authenticated work, and treat screenshots, PDFs, traces, videos, snapshots, console output, and network logs as potentially sensitive files.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:14
Finding

Unpinned Global Installation of a Mutable Dependency

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 14
Vulnerability Type: Supply-chain exposure through an unpinned dependency
Risk Level: Medium

Complete Code Snippet:

bash
npm install -g @playwright/cli@latest
playwright-cli --help

Technical Analysis

The setup instructions install @playwright/cli using the mutable latest npm tag. This does not guarantee that users receive the same reviewed package version each time the command is executed. No lockfile, exact version, or package-integrity value constrains the resolved artifact.

The global installation scope increases the potential impact because the package and its executable are installed into the user's global npm environment. npm package installation can also invoke package lifecycle scripts under the privileges of the user running npm. There is no evidence that the current upstream package is malicious; the vulnerability is the uncontrolled trust placed in whichever release the latest tag resolves to at installation time.

Attack Path

  1. An attacker compromises the upstream npm package, a maintainer account, or the package publication process.
  2. The attacker publishes a modified release and causes the latest tag to resolve to it.
  3. A user follows the documented setup command.
  4. npm downloads and installs the attacker-controlled release globally.
  5. Malicious lifecycle or runtime code executes with the privileges of the installing user when installation occurs or when playwright-cli is invoked.

Impact Assessment

Successful exploitation could execute arbitrary code with the privileges of the user performing the installation. Depending on those privileges, the malicious package could access user-readable files and credentials, alter the user's global npm environment, replace the installed CLI, or affect subsequent browser-automation operations. If the command is run with elevated privileges, the scope could exte ...[truncated 50 chars]

Remediation
View remediation

Remediation Suggestions

  • Replace @latest with an exact, reviewed version, such as @playwright/cli@X.Y.Z.
  • Prefer a project-local dependency managed by a committed lockfile rather than a global installation.
  • Use npm ci in automated environments to enforce lockfile-resolved versions.
  • Verify package provenance and registry integrity before updating the pinned version.
  • Review release notes and package contents before changing the approved version.
  • Avoid running npm installation commands with elevated privileges.
  • Where supported, enforce trusted registries, package allowlists, and dependency-scanning controls.

other

Note
Location
SKILL.md:8
Finding

Remote Audit Badges Disclose Reader Metadata to a Dynamic-DNS Host

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 8-9
Vulnerability Type: External tracking and metadata disclosure
Risk Level: Low

Complete Code Snippet:

markdown
[![No high vulnerabilities found by ClawAudit AI analyse. Click to get more info](https://clawaudit.duckdns.org/badges/f4d4fb45-ed25-4659-8235-2459d0dc8189.png)](https://clawaudit.duckdns.org/audit/f4d4fb45-ed25-4659-8235-2459d0dc8189)
[![No high vulnerabilities found by ClawAudit AI analyse. Click to get more info](https://clawaudit.duckdns.org/badges/a55cb413-b111-4f1a-9f39-a5c857090ebf.png)](https://clawaudit.duckdns.org/audit/a55cb413-b111-4f1a-9f39-a5c857090ebf)

Technical Analysis

The documentation embeds two remotely hosted badge images from clawaudit.duckdns.org. A Markdown renderer that permits remote images may automatically contact this external server when the file is viewed. The server can consequently receive network and request metadata such as the reader's IP address, request time, user agent, and the badge-specific identifier in the URL.

The domain also controls the badge content displayed after the project has been reviewed. Consequently, the visible security claim can change independently of the repository. The links do not execute code by themselves, and no evidence establishes that the current host is malicious; the issue is the avoidable external request and reliance on mutable third-party content.

Attack Path

  1. A user or automated service renders SKILL.md with external image loading enabled.
  2. The renderer requests one or both badge images from clawaudit.duckdns.org.
  3. The external server records available request metadata and the unique badge identifier.
  4. The server may correlate repeated requests or modify the image content shown to future readers.
  5. If a reader follows a badge hyperlink, the host receives an additional navigation request and controls the linked page content.

Impa

...[truncated 450 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove the remote badges if they are not required for the skill's operation.
  • If a visual audit indicator is necessary, store a reviewed static image within the repository.
  • Record audit results as versioned text with a date and scope instead of relying on remotely mutable claims.
  • Configure documentation renderers to block remote images by default.
  • Do not treat third-party badges as authoritative evidence without independently verifying the linked report and provider.
  • If external links must remain, clearly identify them as third-party resources and avoid unique tracking identifiers where possible.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill promotes persistent sessions that retain cookies, storage, auth state, history, and tabs across commands, but it does not warn that this state can contain highly sensitive authentication material and browsing context. Because the skill is specifically designed for browser control, persistent session reuse increases the chance of credential leakage, cross-task contamination, or unintended access if sessions are not isolated and cleaned up carefully.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly instructs the agent to capture traces, videos, screenshots, PDFs, and network logs and save them to disk, but it provides no warning that these artifacts can contain credentials, tokens, personal data, page contents, or authenticated session details. In a browser automation skill, this omission is security-relevant because the artifacts are a normal part of the workflow and may be retained or shared beyond the immediate task.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.