Back to skill

Security audit

浏览器智能代理工具-专业版

Security checks across malware telemetry and agentic risk

Overview

The skill is mostly a disclosed browser automation guide, but it grants broad command/file authority and handles browser sessions with overly broad activation rules and weak safeguards.

Review this skill carefully before installing. Use it only for browser automation tasks you explicitly authorize, avoid running it on unrelated local files or shell tasks, and treat cookies, saved auth files, proxy settings, webhooks, and multi-account workflows as sensitive. Prefer a pinned and trusted agent-browser package source, and do not share or export session state unless you understand where it will be stored and who can access it.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (5)

Context-Inappropriate Capability

Medium
Confidence
92% confidence
Finding
The skill’s declared purpose is browser automation, but the documented '核心功能' expands to generic file processing, API integration, information retrieval, and system command execution. That scope creep materially increases the attack surface and can enable an agent to perform unrelated high-risk actions under the guise of routine browser work, especially because the manifest grants read/write/exec/glob/grep tools.

Intent-Code Divergence

Medium
Confidence
97% confidence
Finding
The documentation asserts commands run in a '安全沙箱' while the manifest exposes unrestricted exec tooling and provides no evidence of actual sandbox enforcement. This can mislead users and downstream agents into treating dangerous shell execution as safe, increasing the likelihood of arbitrary command execution, local file access, or persistence on the host.

Vague Triggers

Medium
Confidence
83% confidence
Finding
The trigger language in the description ('when efficiency, automation, batch processing, workflow optimization are needed') is broad enough to match many ordinary productivity tasks beyond browser automation. Overbroad activation increases the chance that an agent will invoke this powerful skill in unrelated contexts, exposing exec, file, and session-handling capabilities unnecessarily.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The explicit trigger section repeats vague scope language and lacks firm boundaries on when the skill should or should not be selected. Because this skill also exposes high-risk capabilities like exec and session/state handling, ambiguous routing increases the probability of accidental overreach and misuse in contexts with sensitive data or unnecessary system access.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill explicitly supports cookie, storage, session, and multi-account state operations, which directly involve sensitive authentication artifacts, but it does not place prominent warnings and usage constraints at the point of use. In this context, these features are more dangerous because the skill is designed for batch automation and account management, making credential harvesting, session replay, and cross-account misuse more scalable.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.