Back to skill

Security audit

Browser Agent Pro Free

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed browser automation instruction skill with expected screenshot, form-fill, scraping, and logging behavior, though users should be mindful that saved screenshots and logs may contain sensitive page or form data.

Install only if you are comfortable with browser pages, screenshots, scraped data, and operation logs being saved under ~/workspace/browser. Avoid using it on sensitive logged-in sessions or personal-data forms unless you intend to retain those records, and periodically delete or configure retention for stored screenshots and logs.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The skill is scoped as a generic natural-language browser automation capability with very broad applicability and few hard limits on when it should or should not be invoked. In agent environments, ambiguous activation can cause the skill to trigger on loosely related prompts and perform web actions, data collection, or form interaction unexpectedly, increasing the risk of privacy-impacting or unintended external actions.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The capability coverage section includes fragmented, generic trigger keywords such as 'Agent', 'Use', 'LLM', and '智能对话', which can make matching logic overbroad and non-deterministic. In a tool-using agent, this creates a realistic risk of accidental skill activation in conversations that merely mention AI, browsers, or automation, leading to unintended browsing, scraping, or persistence of page content.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly persists screenshots, scraped data, and operation logs under a workspace path, but it does not clearly disclose the privacy, confidentiality, and retention risks of storing page contents and user-entered data. Because browser automation often touches personal, internal, or session-derived content, silent persistence can expose sensitive information to other tools, users, or later processing steps.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The form-filling workflow says it will take screenshots after filling and keep logs, but it does not explicitly warn that personal data entered into fields may be captured in those screenshots and potentially reflected in logs or stored artifacts. In this context, the skill is designed to handle names, phone numbers, addresses, and similar PII, so persistence of completed forms creates a direct confidentiality risk.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.