Back to skill

Security audit

Chrome Bookmarks

Security checks for vulnerabilities and agentic risk

Overview

This skill does what it advertises: it reads local Chrome bookmarks and can open a matching bookmark, with some ordinary caution needed around opening fuzzy matches.

Install only if you are comfortable letting the assistant read your Chrome bookmarks and open a bookmarked URL on request. For ambiguous names, search first and choose an exact result; avoid vague open commands if your bookmarks include sensitive internal links or non-http URL schemes.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (7)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill description emphasizes searching and browsing bookmarks, but the documented behavior also launches URLs via the system open command. That mismatch matters because active command execution can trigger navigation to arbitrary bookmarked sites, enabling phishing, tracking, or unintended execution chains via registered URL handlers, especially when the user may believe the skill is only performing passive local reads.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill uses sensitive capabilities—local file access to Chrome bookmark data, environment/path discovery, and shell execution—but does not declare any explicit tool scope or permission boundaries. This is dangerous because an agent may invoke broader capabilities than users or reviewers expect, reducing transparency and increasing the risk of unintended local data access or command execution.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
91% confidence
Finding

The code launches the bookmarked URL via a subprocess using the platform opener without validating the URL scheme or requiring confirmation. Because bookmark contents are treated as trusted local data, a malicious or previously poisoned bookmark could trigger opening unsafe schemes or unexpected local/application handlers, causing unintended actions when the skill is invoked.

Content

Scanner excerpt · scripts/chrome_bookmarks.py (reported line 220)May include surrounding context.

python
idx = int(keyword_or_index)
        if 0 <= idx < len(all_bm):
            url = all_bm[idx]["url"]
            subprocess.Popen(["open", url])
            return {"opened": True, "url": url, "name": all_bm[idx]["name"]}
    except ValueError:
        pass

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest describes a Chrome bookmarks skill that reads the local bookmarks file directly and presents itself as generally applicable, while path detection explicitly supports multiple platforms. However, actually opening a bookmark is hard-coded to invoke open, which is specific to macOS and does not match the broader cross-platform behavior implied by the skill description and surrounding code.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill can launch a bookmark directly from assistant-driven input without an explicit warning or confirmation step. In this context, that makes accidental navigation, phishing opens, and triggering unsafe URI handlers more likely, especially when results are chosen by fuzzy keyword matching rather than a deliberate user selection.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
91% confidence
Finding

This path opens the first keyword-matched bookmark without additional user verification or URL validation. In an assistant context, fuzzy matching can make accidental or adversarially selected bookmarks open automatically, increasing the risk of phishing, local file access, or invocation of registered custom URI handlers.

Content

Scanner excerpt · scripts/chrome_bookmarks.py (reported line 229)May include surrounding context.

python
keyword_lower = keyword_or_index.lower()
    for bm in all_bm:
        if keyword_lower in bm["name"].lower() or keyword_lower in bm["url"].lower():
            subprocess.Popen(["open", bm["url"]])
            return {"opened": True, "url": bm["url"], "name": bm["name"]}

    return {"opened": False, "error": f"No bookmark found matching '{keyword_or_index}'"}

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The stated purpose is to search, browse, and open Chrome bookmarks by reading the local Chrome Bookmarks JSON file directly. Instead of operating on one known bookmarks file, the code scans the Chrome user data directory and inspects available profile folders to locate candidate bookmark files, which is a broader local filesystem discovery capability than the manifest emphasizes.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.