Back to skill

Security audit

Agent Browser Automation

Security checks across malware telemetry and agentic risk

Overview

This browser automation skill is mostly documentation-only, but it promotes anti-bot bypass and gives broad command/browser authority without enough user-control boundaries.

Review this skill carefully before installing. Use it only for websites and workflows you are authorized to automate, avoid anti-bot or access-control bypass, and require explicit user approval before logging in, submitting forms, uploading files, or running shell commands through it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (4)

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
The skill explicitly advertises '反爬虫策略自动绕过' as a paid capability, which goes beyond ordinary browser automation and encourages evasion of website defenses. In a browser automation skill with read/exec/write tools, this increases the likelihood of misuse against sites that rely on anti-bot controls for abuse prevention, fraud reduction, or access control.

Intent-Code Divergence

Medium
Confidence
90% confidence
Finding
The documentation claims only whitelisted commands should be executed, but the skill declares a general exec capability and shows shell-style command usage without any visible whitelist, policy, or enforcement mechanism. That mismatch can lead operators or downstream agents to assume command execution is constrained when it is not, increasing the risk of arbitrary command execution, unsafe argument handling, or misuse of the host environment.

Vague Triggers

Medium
Confidence
81% confidence
Finding
The activation guidance is extremely broad, stating the skill should be used whenever AI models, agent orchestration, or LLM applications are involved. Overbroad triggering can cause the skill to be invoked in unrelated contexts, leading to unnecessary browsing, command execution, or external data transmission in situations where a safer or narrower tool should have been selected.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The usage instructions tell the agent to navigate, click, input, and extract from websites, but they do not clearly warn users that these actions may transmit prompts, credentials, form contents, cookies, or other data to third-party services. In the context of a browser automation skill, omission of that notice is dangerous because users may not realize that invoking the skill causes real external interactions and potentially irreversible side effects.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.