Back to skill

Security audit

browser-automation

Security checks for vulnerabilities and agentic risk

Overview

This browser automation skill is coherent, but it asks for broad browser authority with remote AI processing, persistent authenticated browser state, automatic downloads, and incomplete install artifacts that users should review carefully.

Install only if you are comfortable with a powerful browser automation skill that can interact with arbitrary sites and accounts. Avoid entering real passwords or sensitive data through natural-language actions, avoid authenticated or internal sites unless you understand the external API routing, use an isolated browser profile, clean downloads and screenshots, and do not run npm install/npm link unless you have independently verified the missing package source and lockfile.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

other

Error
Location
EXAMPLES.md:114
Finding

Credentials and Sensitive Page Data May Be Exposed to an External AI Service

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
REFERENCE.md:458
Finding

Persistent Authenticated Browser Profile Has Unrestricted Internal Network Reach

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
REFERENCE.md:380
Finding

Automatic Unrestricted Downloads Permit Untrusted Files to Enter the Workspace

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:24
Finding

Setup Instructions Invoke an Absent and Unauditable Node.js Package

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (15)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill automatically switches to a remote browser service whenever an API key is present, with no user warning or consent, which can silently transmit browsing actions, page contents, form inputs, and potentially sensitive session data to a third party. This is especially risky because the behavior is implicit and environment-driven, so the user may believe actions are occurring locally when they are not.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 77)May include surrounding context.

md
For API reference, see [REFERENCE.md](REFERENCE.md).

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 18)May include surrounding context.

md
"apiKey": {
      "required": true,
      "configured": false,
      "description": "SKILLBOSS_API_KEY exported (i.e $SKILLBOSS_API_KEY) or in .env file"
    },
    "browserCommand": {
      "required": true,

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · setup.json (reported line 17)May include surrounding context.

json
"apiKey": {
      "required": true,
      "configured": false,
      "description": "SKILLBOSS_API_KEY exported (i.e $SKILLBOSS_API_KEY) or in .env file"
    },
    "browserCommand": {
      "required": true,

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · setup.json (reported line 29)May include surrounding context.

json
"apiKey": {
      "required": true,
      "configured": false,
      "description": "SKILLBOSS_API_KEY exported (i.e $SKILLBOSS_API_KEY) or in .env file"
    },
    "browserCommand": {
      "required": true,

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The login example instructs entering credentials and then taking a screenshot of an authenticated dashboard without warning about capture of personal or account data. In browser automation systems, screenshots, logs, and stored session state can expose secrets, PII, internal application data, or account context to operators or later tasks.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The note explicitly states that Chrome's user profile may preserve session cookies between runs, enabling cross-task session reuse. In an agent context, persistent authenticated state can cause unintended access to prior users' accounts or leakage of sensitive session data across otherwise separate operations.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest describes browsing, navigating pages, extracting data, screenshots, form filling, clicking buttons, and interacting with web applications. Example 6 adds downloading arbitrary files to a local directory, which is a distinct local file acquisition capability not explicitly covered by that stated purpose.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The README describes the skill in very broad terms—'browse websites, navigate web pages, extract data from websites, take screenshots, fill forms, click buttons, or interact with web applications'—without any boundaries, allowlists, or user-confirmation requirements. In an agentic environment, this can cause over-triggering on common web-related prompts and lead the skill to access arbitrary sites, submit forms, or extract sensitive content when a narrower skill invocation policy was intended.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The act command uses AI-driven natural-language actions that can click buttons, type into forms, press keys, and otherwise interact with live web applications, but the reference does not clearly warn that these actions may submit forms, trigger transactions, or modify account data. Because the tool uses model-based element selection and explicitly notes it may act on the wrong element if underspecified, the risk of unintended state-changing actions is materially elevated.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The Stagehand configuration explicitly routes browser actions and extraction through the external SkillBoss API Hub, meaning page content, element context, and possibly sensitive session-derived data may be transmitted off-host to a third-party service. In this browser skill, that is more dangerous because the browser has access to authenticated pages, persistent cookies, internal resources, and user-entered data, so external model calls can expose sensitive information beyond the local environment.

Content

Scanner excerpt · REFERENCE.md (reported line 347)May include surrounding context.

md
env: "LOCAL",
  verbose: 0,
  enableCaching: true,
  model: "skillboss/auto",  // routed via SkillBoss API Hub (https://api.heybossai.com/v1/pilot)
  localBrowserLaunchOptions: {
    cdpUrl: wsUrl,
  },

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documentation states that downloads begin automatically and are written to ./agent/downloads without any file type restrictions, which creates a silent disk-write capability. In a browser automation skill with full network access, this increases the risk of unintentionally saving untrusted or malicious content to the local filesystem without explicit operator awareness or confirmation.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
84% confidence
Finding

The version information reiterates that the model is auto-routed via an external API endpoint, reinforcing that the skill depends on a third-party service for browser actions. While primarily informational, this confirms a real data egress path that can expose browsed content and interaction context when users may assume the browser operates entirely locally.

Content

Scanner excerpt · REFERENCE.md (reported line 530)May include surrounding context.

md
## Version Information

- **Stagehand**: Uses `@browserbasehq/stagehand` package v2.5.2+
- **Model**: SkillBoss API Hub (auto-routed via https://api.heybossai.com/v1/pilot) for browser actions
- **CLI Tool**: TypeScript CLI in `src/cli.ts`
- **Agent SDK**: SkillBoss API Hub SDK for conversation framework
- **Browser**: Local Chrome/Chromium installation

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The activation description is very broad and overlaps with many ordinary browsing-related user requests, increasing the chance this skill is invoked in contexts where safer, more privacy-preserving tools or workflows would be preferable. In combination with the skill's ability to automate navigation, extraction, and form interaction, broad routing can lead to overuse of a powerful browser automation capability without explicit user intent or awareness.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The download example notes that files are automatically written to a local directory, but it does not clearly warn users about persistence, possible sensitive-file retention, or the risk of downloading untrusted content. This can lead to accidental storage of confidential documents or unsafe files on the host running the agent.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.