Back to skill

Security audit

浏览器代理助手

Security checks for vulnerabilities and agentic risk

Overview

This skill appears to be a browser automation and data collection helper, but it requests broad local command and file authority with vague activation rules and incomplete scoping.

Review this skill before installing. It is not clearly malicious, but it should only be used when you intentionally want browser automation or web data collection, and you should avoid granting it broad command execution, file write access, credentials, proxies, or scraping tasks without explicit limits.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Description-Behavior Mismatch

High
Confidence
95% confidence
Finding
The manifest presents the skill as a generic API wrapper, while the body describes browser automation, scraping, custom JavaScript, proxying, multithreading, and command-capable operation. This mismatch can cause agents or users to grant broader trust and permissions than intended, enabling risky automation behavior under a misleading label.

Context-Inappropriate Capability

Medium
Confidence
92% confidence
Finding
The skill advertises exec, read, write, glob, and grep despite describing itself primarily as an API invocation tool. Unjustified local command and filesystem capabilities increase the blast radius of misuse, especially if an agent invokes the skill assuming it only performs remote API calls.

Intent-Code Divergence

Medium
Confidence
90% confidence
Finding
The documentation materially contradicts itself by calling the skill an API wrapper while the detailed sections describe browser interaction and scraping workflows. Such contradictions undermine informed consent and safe policy routing, making it easier for an agent to select the skill in contexts where those stronger capabilities are inappropriate.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The activation guidance targets very broad, common AI scenarios such as model calling, chat, orchestration, and LLM applications. Overbroad triggers can cause frequent or unintended activation of a high-capability skill, increasing the chance of unnecessary external calls, browser actions, or privileged operations.

Vague Triggers

Medium
Confidence
82% confidence
Finding
The trigger phrase 'Use when 用户说"Agent B"' is ambiguous and underspecified, making accidental or context-free activation more likely. Ambiguous triggers are especially risky here because the skill exposes powerful behaviors including browser interaction and local tooling.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill advertises file writing, command execution, and external API use without prominent user-facing warnings about data exfiltration, filesystem modification, credential exposure, or unsafe command effects. In the context of a browser automation agent with script and proxy support, the absence of strong warnings and guardrails materially increases misuse risk.

Static analysis

No suspicious patterns detected.