other
- Location
EXAMPLES.md:114- Finding
Credentials and Sensitive Page Data May Be Exposed to an External AI Service
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This browser automation skill is coherent, but it asks for broad browser authority with remote AI processing, persistent authenticated browser state, automatic downloads, and incomplete install artifacts that users should review carefully.
Install only if you are comfortable with a powerful browser automation skill that can interact with arbitrary sites and accounts. Avoid entering real passwords or sensitive data through natural-language actions, avoid authenticated or internal sites unless you understand the external API routing, use an isolated browser profile, clean downloads and screenshots, and do not run npm install/npm link unless you have independently verified the missing package source and lockfile.
EXAMPLES.md:114Credentials and Sensitive Page Data May Be Exposed to an External AI Service
REFERENCE.md:458Persistent Authenticated Browser Profile Has Unrestricted Internal Network Reach
REFERENCE.md:380Automatic Unrestricted Downloads Permit Untrusted Files to Enter the Workspace
SKILL.md:24Setup Instructions Invoke an Absent and Unauditable Node.js Package
The skill automatically switches to a remote browser service whenever an API key is present, with no user warning or consent, which can silently transmit browsing actions, page contents, form inputs, and potentially sensitive session data to a third party. This is especially risky because the behavior is implicit and environment-driven, so the user may believe actions are occurring locally when they are not.
Referenced artifact was not completely inspected
For API reference, see [REFERENCE.md](REFERENCE.md).
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
"apiKey": {
"required": true,
"configured": false,
"description": "SKILLBOSS_API_KEY exported (i.e $SKILLBOSS_API_KEY) or in .env file"
},
"browserCommand": {
"required": true,
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
"apiKey": {
"required": true,
"configured": false,
"description": "SKILLBOSS_API_KEY exported (i.e $SKILLBOSS_API_KEY) or in .env file"
},
"browserCommand": {
"required": true,
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
"apiKey": {
"required": true,
"configured": false,
"description": "SKILLBOSS_API_KEY exported (i.e $SKILLBOSS_API_KEY) or in .env file"
},
"browserCommand": {
"required": true,
The login example instructs entering credentials and then taking a screenshot of an authenticated dashboard without warning about capture of personal or account data. In browser automation systems, screenshots, logs, and stored session state can expose secrets, PII, internal application data, or account context to operators or later tasks.
The note explicitly states that Chrome's user profile may preserve session cookies between runs, enabling cross-task session reuse. In an agent context, persistent authenticated state can cause unintended access to prior users' accounts or leakage of sensitive session data across otherwise separate operations.
The manifest describes browsing, navigating pages, extracting data, screenshots, form filling, clicking buttons, and interacting with web applications. Example 6 adds downloading arbitrary files to a local directory, which is a distinct local file acquisition capability not explicitly covered by that stated purpose.
The README describes the skill in very broad terms—'browse websites, navigate web pages, extract data from websites, take screenshots, fill forms, click buttons, or interact with web applications'—without any boundaries, allowlists, or user-confirmation requirements. In an agentic environment, this can cause over-triggering on common web-related prompts and lead the skill to access arbitrary sites, submit forms, or extract sensitive content when a narrower skill invocation policy was intended.
The act command uses AI-driven natural-language actions that can click buttons, type into forms, press keys, and otherwise interact with live web applications, but the reference does not clearly warn that these actions may submit forms, trigger transactions, or modify account data. Because the tool uses model-based element selection and explicitly notes it may act on the wrong element if underspecified, the risk of unintended state-changing actions is materially elevated.
The Stagehand configuration explicitly routes browser actions and extraction through the external SkillBoss API Hub, meaning page content, element context, and possibly sensitive session-derived data may be transmitted off-host to a third-party service. In this browser skill, that is more dangerous because the browser has access to authenticated pages, persistent cookies, internal resources, and user-entered data, so external model calls can expose sensitive information beyond the local environment.
env: "LOCAL",
verbose: 0,
enableCaching: true,
model: "skillboss/auto", // routed via SkillBoss API Hub (https://api.heybossai.com/v1/pilot)
localBrowserLaunchOptions: {
cdpUrl: wsUrl,
},
The documentation states that downloads begin automatically and are written to ./agent/downloads without any file type restrictions, which creates a silent disk-write capability. In a browser automation skill with full network access, this increases the risk of unintentionally saving untrusted or malicious content to the local filesystem without explicit operator awareness or confirmation.
The version information reiterates that the model is auto-routed via an external API endpoint, reinforcing that the skill depends on a third-party service for browser actions. While primarily informational, this confirms a real data egress path that can expose browsed content and interaction context when users may assume the browser operates entirely locally.
## Version Information
- **Stagehand**: Uses `@browserbasehq/stagehand` package v2.5.2+
- **Model**: SkillBoss API Hub (auto-routed via https://api.heybossai.com/v1/pilot) for browser actions
- **CLI Tool**: TypeScript CLI in `src/cli.ts`
- **Agent SDK**: SkillBoss API Hub SDK for conversation framework
- **Browser**: Local Chrome/Chromium installation
The activation description is very broad and overlaps with many ordinary browsing-related user requests, increasing the chance this skill is invoked in contexts where safer, more privacy-preserving tools or workflows would be preferable. In combination with the skill's ability to automate navigation, extraction, and form interaction, broad routing can lead to overuse of a powerful browser automation capability without explicit user intent or awareness.
The download example notes that files are automatically written to a local directory, but it does not clearly warn users about persistence, possible sensitive-file retention, or the risk of downloading untrusted content. This can lead to accidental storage of confidential documents or unsafe files on the host running the agent.
No suspicious patterns detected.