Back to skill

Security audit

browser-automation-v2

Security checks for vulnerabilities and agentic risk

Overview

The skill is a browser automation package with broad local authority and review-worthy scope issues, including anti-crawler bypass language and unrelated file/API/command capabilities.

Install only if you are comfortable granting an agent browser automation plus local read/write/exec authority. Use it for user-directed, authorized websites and review any commands, API calls, screenshots, and exported data; avoid using it to bypass site protections or automate sensitive authenticated pages without explicit controls.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (5)

Context-Inappropriate Capability

Medium
Confidence
93% confidence
Finding
The skill explicitly advertises '反爬虫策略自动绕过' (anti-crawler bypass), which signals capability to evade website protections rather than merely automate legitimate browsing. In a browser automation skill, this expands use toward policy evasion and potentially unauthorized scraping, increasing abuse potential beyond the stated business automation purpose.

Description-Behavior Mismatch

High
Confidence
95% confidence
Finding
The manifest and description present the skill as browser automation, but later sections add file processing, external API integration, and system command execution. This hidden scope expansion is dangerous because it grants users and downstream agents a much broader operational surface than expected, including host-impacting actions and data exfiltration paths.

Description-Behavior Mismatch

Medium
Confidence
89% confidence
Finding
The efficiency section normalizes API automation and command execution as part of this browser skill, reinforcing a broader capability set than users would infer from the name and summary. That mismatch can cause unsafe invocation, where an agent selects this skill for general automation and inadvertently enables sensitive system or network operations.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The activation language is extremely broad ('提高效率、自动化流程、批量处理、工作流优化'), making the skill eligible for many generic productivity requests. In agentic environments, overly broad routing language can cause over-selection of a high-privilege skill containing read, write, and exec tools, increasing the chance of unnecessary sensitive actions.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The documentation describes browser interaction, extraction, and screenshots, while elsewhere also referencing file handling, APIs, and command execution, but does not provide clear user-facing warnings about privacy, credential handling, website terms, or host/system impact. This omission is dangerous because users may invoke the skill on sensitive pages or data without understanding collection, retention, or execution risks.

Static analysis

No suspicious patterns detected.