Back to skill

Security audit

browser-automation-tool-free

Security checks across malware telemetry and agentic risk

Overview

This is a browser automation skill, but its scope and remote-browser behavior are not clearly constrained enough for the authority it requests.

Install only if you are comfortable giving an agent browser-control authority. Prefer local Chrome mode, remove Browserbase credentials unless you intentionally want remote execution, and require explicit confirmation before logging in, entering credentials, submitting forms, purchasing, posting, or changing account data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Description-Behavior Mismatch

Medium
Confidence
90% confidence
Finding
The skill is presented as a free local-Chrome tool, but it also documents optional remote browser service usage with external API keys. This mismatch can mislead users about where their browser actions and page data may be sent, increasing the risk of unintended data transmission to third-party infrastructure.

Intent-Code Divergence

Medium
Confidence
89% confidence
Finding
The documentation states the free edition defaults to local Chrome, but later sections describe active Browserbase remote mode support and troubleshooting as if it is part of normal operation. This inconsistency weakens informed consent and can cause operators to assume local-only execution when remote services may be involved.

Vague Triggers

Medium
Confidence
81% confidence
Finding
The trigger conditions are broad enough to invoke the skill for general coding, debugging, testing, and deployment situations that exceed browser automation needs. Overbroad activation increases the chance the agent will use a high-impact tool with exec/write capabilities in contexts where browser interaction is unnecessary, leading to unintended actions on websites or local systems.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill lacks a clear warning that natural-language browser actions can click buttons, submit forms, log into accounts, and potentially send page contents or credentials to remote services when configured. In a browser automation context, omission of these safety notices raises the risk of account changes, data leakage, or unintended transactions.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.