Back to skill

Security audit

Browser Automation

Security checks across malware telemetry and agentic risk

Overview

This browser automation skill is broadly useful, but it also promotes anti-bot bypass and gives under-scoped automation guidance that users should review carefully before installing.

Install only if you intend to use it on sites and accounts where you have authorization. Avoid using the anti-bot bypass, proxy, or User-Agent evasion guidance against third-party sites, and require explicit user confirmation before logins, form submissions, account changes, purchases, messages, or extraction of private data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
The skill explicitly markets '反爬虫策略自动绕过' as a premium capability, which goes beyond ordinary browser automation and normalizes bypassing site defenses. In the context of a generic automation skill with exec access, this increases misuse potential for scraping protected targets or violating site controls.

Context-Inappropriate Capability

Medium
Confidence
97% confidence
Finding
The error-handling guidance recommends proxies, User-Agent changes, and related tactics to avoid detection, which are classic evasion techniques rather than necessary automation functionality. This materially facilitates abusive automation against third-party sites and undermines transparency and accountability.

Vague Triggers

High
Confidence
91% confidence
Finding
The activation condition 'Use when the user asks' and broad efficiency language provide almost no scoping constraints, so the skill may be invoked for sensitive or destructive browser actions without adequate review. For a tool that can drive browser interactions and execute commands, ambiguous triggering significantly raises the chance of unsafe automation affecting external systems or private accounts.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The core capability section repeats a vague invocation rule without defining operational boundaries, allowed targets, or prohibited actions. That ambiguity makes misuse easier because the skill appears appropriate for any browser-driven objective, including risky or unauthorized tasks.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill describes navigation, clicking, input, extraction, proxy configuration, and retries without warning users that these actions can affect external systems, expose session data, or automate actions on behalf of a user. In a browser automation context, missing safety disclosures increases the risk of unintended state changes, privacy violations, and non-consensual interactions with websites.

Ssd 4

Medium
Confidence
94% confidence
Finding
Framing anti-bot bypass as a premium workflow capability encourages progressive misuse and commercializes evasion behavior within the skill's normal operation. This is more dangerous in a browser automation skill because it pairs broad automation with incentives to defeat target-site protections.

Ssd 4

Medium
Confidence
96% confidence
Finding
The troubleshooting section teaches users how to respond to defenses by lowering detection and changing identifiers, which operationalizes evasion rather than merely describing errors. In context, this acts as step-by-step abuse enablement for scraping or interacting with protected sites at scale.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.