Back to skill

Security audit

LexMount Cloud Browser

Security checks for vulnerabilities and agentic risk

Overview

The skill is a disclosed cloud-browser integration, but users should understand it installs and uses a LexMount CLI that can handle logged-in browser sessions.

Install this only if you are comfortable authorizing LexMount's cloud browser service and letting it handle the pages, screenshots, downloads, form data, and optional logged-in website contexts you ask it to use. Review the downloaded CLI provenance in your environment if supply-chain control is important, and use dedicated browser Contexts for sensitive accounts.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (10)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 16)May include surrounding context.

md
将 `<skill-root>` 替换为本次加载的 `SKILL.md` 所在目录:

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 19)May include surrounding context.

md
将 `<skill-root>` 替换为本次加载的 `SKILL.md` 所在目录:

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 23)May include surrounding context.

md
将 `<skill-root>` 替换为本次加载的 `SKILL.md` 所在目录:

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/authentication.md (reported line 14)May include surrounding context.

CLI 在 127.0.0.1 绑定随机回调端口,生成 PKCE 校验信息和 state,打开 LexMount 授权页,收到一次性 code 后换取凭据,并保存到:

text
~/.config/lexmount/browser-cli/credentials.json

Unix 上文件权限为 0600。CLI 对 JSON 输出中的 API Key 做脱敏;不要另外读取并回显凭据文件。

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/authentication.md (reported line 24)May include surrounding context.

CLI 在 127.0.0.1 绑定随机回调端口,生成 PKCE 校验信息和 state,打开 LexMount 授权页,收到一次性 code 后换取凭据,并保存到:

text
~/.config/lexmount/browser-cli/credentials.json

Unix 上文件权限为 0600。CLI 对 JSON 输出中的 API Key 做脱敏;不要另外读取并回显凭据文件。

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill instructs the agent to execute shell commands such as bootstrap, doctor, auth, and browser session operations, but it does not declare any explicit tool scope or allowed-tools boundary. That mismatch weakens security controls because a host agent may expose shell execution more broadly than intended, making it easier for an adversarial or modified skill to run unreviewed commands under the guise of normal setup.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The default prompt invokes the cloud browser with an open-ended natural-language instruction and no visible constraints on when or how the skill should be triggered. Because this skill can open arbitrary webpages, read content, fill forms, take screenshots, and reuse authenticated sessions, a broad default invocation increases the chance of overbroad activation, unintended navigation, or sensitive data exposure in downstream agent use.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

该文件整体以中文编写并直接面向操作者给出指令,但未说明这是可选语言、需用户明确选择,或该技能仅限中文使用场景。根据语言/locale 政策,若技能实质上强制单一语言而无 opt-in 或合理地域限定,属于自然语言政策违规。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The entire troubleshooting guide is written in Chinese and does not indicate that language selection is optional or user-configurable. Per the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is clearly documented and justified.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/bootstrap.sh (reported line 33)May include surrounding context.

sh
install_dir="${LEXMOUNT_BROWSER_CLI_INSTALL_DIR:-$skill_dir/bin}"
mkdir -p "$install_dir"
cp "$tmp_dir/$asset" "$install_dir/browser-cli"
chmod 0755 "$install_dir/browser-cli"
"$install_dir/browser-cli" version
echo "Installed browser-cli to $install_dir/browser-cli"

Static analysis

No suspicious patterns detected.