Back to skill

Security audit

browser-testing-with-devtools

Security checks across malware telemetry and agentic risk

Overview

The skill appears to be a browser-testing helper, but its instructions are overly generic and ask for broad command/file authority and possible API credentials without clear scope.

Review this skill before installing. It is not clearly malicious, but it should be limited to explicit browser-testing tasks, and users should not provide API keys, credentials, administrator execution, or unrelated file/command access unless the publisher documents exactly why those are required.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Intent-Code Divergence

Medium
Confidence
90% confidence
Finding
The skill is presented as a Chrome DevTools browser-testing capability, but later configuration guidance tells users to set generic API keys and establish unspecified API connections. This mismatch can cause operators or orchestration systems to provision unnecessary secrets or connect the skill to unrelated services, expanding attack surface and enabling credential misuse if the template is followed blindly.

Intent-Code Divergence

Medium
Confidence
88% confidence
Finding
The recovery guidance includes unrelated failure modes such as API authentication, rate limiting, file handling, and generic command execution errors that do not align with the stated browser-testing function. In a security context, contradictory operational instructions are dangerous because they normalize broader permissions and behaviors than necessary, increasing the likelihood of misuse, overbroad automation, or hidden capability abuse going unnoticed.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger condition 'when the user needs to perform related operations' is so broad that the skill may activate for many unrelated requests. Because this skill exposes powerful tools including exec and read, vague routing materially increases the chance of unintended invocation, tool overreach, and unsafe execution in contexts where browser testing was not actually requested.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.