Back to skill

Security audit

Agent Browser Automation

Security checks for vulnerabilities and agentic risk

Overview

This browser automation skill is not clearly malicious, but it asks for broad command and file powers with weak scoping and administrator-run guidance.

Review this before installing. Use it only in a sandboxed workspace, avoid authenticated or sensitive sites unless you explicitly intend that access, do not run it as administrator, and require confirmation before file writes, command execution, data export, or interactions that affect third-party websites.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:24
Finding

Overbroad Tool Permissions and Unsafe Privilege-Escalation Guidance

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 24–27, 254–256, 269, and 291
Vulnerability Type: Excessive system capabilities and privilege-escalation guidance
Risk Level: Medium

Vulnerable Code

Lines 24–27 declare unrestricted general-purpose file and command-execution tools:

yaml
tools:
- read
- exec
- write

Lines 254–256 further state that the Skill supports reading and writing files and executing system commands. Lines 269 and 291 recommend running with administrator privileges when file permissions are insufficient.

Technical Analysis

The Skill is presented as browser automation, but it requests generic filesystem read, filesystem write, and command-execution capabilities without defining command allowlists, path restrictions, sandbox boundaries, or approval requirements. These capabilities exceed what is strictly required for browser navigation and page extraction.

The document also recommends administrator execution as a generic remedy for insufficient file permissions. Elevating the entire agent or automation environment rather than correcting the specific permission boundary violates the principle of least privilege. If untrusted task input or webpage content influences agent actions, these broad tools could be used against resources unrelated to the browser-automation task.

The document claims commands run in a secure sandbox, but it does not provide an enforceable sandbox configuration. Documentation alone does not establish a security boundary.

Attack Path

  1. A user submits an automation request involving an attacker-controlled website, or the browser encounters attacker-controlled page content.
  2. The content induces the agent to read a local file, write an unrelated file, or invoke a system command as part of the purported automation workflow.
  3. The Skill's declared read, write, and exec tools permit the agent to attempt the requested operation.

...[truncated 1163 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove generic read, write, and exec capabilities unless each capability is necessary for a documented browser operation.
  2. Replace unrestricted command execution with a narrow interface that exposes only approved agent-browser subcommands and validated arguments.
  3. Enforce a command allowlist and reject shell metacharacters, command substitution, redirects, pipelines, and arguments derived directly from untrusted page content.
  4. Restrict filesystem operations to a dedicated workspace using canonical-path validation, deny path traversal, and prohibit access to credentials, configuration directories, and system files.
  5. Require explicit user confirmation before downloads, file writes, command execution, authentication actions, or other externally visible side effects.
  6. Remove the recommendation to run as administrator. Troubleshooting should instead identify the required resource and grant only the minimum specific permission.
  7. Implement the claimed sandbox as an enforceable control, such as an unprivileged container with a read-only root filesystem, isolated temporary storage, restricted networking, and no host credential mounts.
  8. Treat webpage text and extracted content as untrusted data rather than agent instructions.
  9. Document the required agent-browser version and installation source so the external executable can be independently verified.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description uses very broad activation language such as applying whenever AI models, agent orchestration, or LLM apps are involved. This can cause the skill to be selected in unrelated contexts, increasing the chance that a high-risk capability set (browser automation, exec, write, data extraction) is invoked without a narrowly scoped user need or informed consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill advertises browser automation, command execution, file writes, and data extraction, but the warning language is weak and buried later in the document instead of clearly informing users up front about privacy, credential exposure, system modification, and website interaction risks. In context, this is more dangerous because the skill exposes read/exec/write tools and includes examples that can operate on arbitrary sites, making misuse or accidental sensitive-data handling more likely.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.