Back to skill

Security audit

Dexter Browser Automation

Security checks for vulnerabilities and agentic risk

Overview

This is a functional browser automation skill, but it needs Review because it allows broad web interaction, credential entry, local file writes, and unsandboxed arbitrary navigation without enough safeguards.

Install only if you are comfortable reviewing and sandboxing browser automation. Run it as an unprivileged user in an isolated environment with restricted network access, avoid passing passwords or secrets on the command line, do not use it for purchases, account changes, or authenticated workflows without explicit confirmation, and pin the Playwright/browser versions before use.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/extract.py:22
Finding

Unrestricted URL Navigation with Chromium Sandbox Disabled

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:115
Finding

Sensitive Form Values Are Passed Through Process Arguments and Returned in Output

Content
View full analysis
3 and action == "fill" else None url = sys.argv[-1] if len(sys.argv) > 3 and action != "fill" else (sys.argv[4] if len(sys.argv) > 4 else None) result = interact(action, selector, value, url) print(json.dumps(result, indent=2)) ``` ### Technical Analysis Command-line arguments are commonly exposed through shell history, process inspection interfaces, orchestration metadata, audit systems, and Agent tool-call logs. The script compounds this exposure by copying the supplied value into its JSON response and printing it. Although transmitting a password to a caller-selected login page can be part of the declared form-automation functionality, retaining the plaintext value in process arguments and returning it in output are unnecessary. These behaviors exceed the minimum data exposure needed to fill a form. The implementation also does not distinguish ordinary form text from sensitive selectors such as password fields, so all filled values are treated as loggable data. ### Attack Path 1. A user follows the documented login example and passes a password as ...[truncated 970 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:146
Finding

Unpinned Playwright and Chromium Installation Without Integrity Verification

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/screenshot.py:25
Finding

Caller-Controlled Screenshot Path Allows Arbitrary Writable-File Overwrite

Content
View full analysis
2 else "/tmp/screenshot.png" result = screenshot(url, path) ``` ### Technical Analysis The caller can select any filesystem path writable by the process. The implementation does not constrain output to a dedicated directory, canonicalize and validate the path, reject symbolic links, prevent overwriting, or create a private randomized file. Playwright writes PNG data to the selected path. This does not provide control over arbitrary file contents, but it can replace or corrupt existing writable files. The fixed default `/tmp/screenshot.png` additionally allows collisions between users or concurrent executions and may be exposed to symbolic-link or race-condition issues in a shared temporary directory. Allowing a caller to choose an output filename may be useful, but unrestricted filesystem access exceeds what is required to save a screenshot. ### Attack Path 1. An attacker controls or influences the screenshot output argument. 2. The attacker chooses an existing file writable by the Skill process, or prepares a symbolic link at the predictable default temporary path. 3. The script invokes `page.screenshot(path=path, ...)`. 4. Chromium writes PNG content to the resolved destination. 5. The target file is replaced or corrupted, potentially ...[truncated 527 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (17)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description presents this skill as a general browser automation/interactivity tool for JS-rendered pages, emphasizing user interaction and screenshots as the reasons to use it. The supplied code does not implement browser interaction flows or screenshot capture. Instead, its concrete and primary function is targeted data extraction from page elements using a CSS selector. While Playwright is used and the page may be JS-rendered, the code's actual purpose aligns more with extraction/scraping than an interactive browser last-resort tool. This is a material description-behavior mismatch.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill documents shell-executable scripts but does not declare any tool scope such as allowed tools or permissions. In an agent environment, missing scope boundaries can let the skill invoke broader shell capabilities than intended, increasing the chance of misuse, unsafe command execution, or policy bypass. Because this skill is explicitly a last-resort browser automation layer that launches scripts, the absence of explicit restrictions is more dangerous than in a purely informational skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The documentation instructs users to perform click and fill actions, including login-style workflows, without warning that these actions can change remote state, submit forms, trigger purchases, send messages, or alter accounts. In a browser automation skill, omission of these warnings is dangerous because operators may treat the tool as read-only when it is actually capable of write-side effects on third-party services.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The example login flow includes entering credentials and scraping a dashboard without any guidance on secret handling, consent, storage, or privacy boundaries. This normalizes passing sensitive credentials through command arguments and encourages authenticated scraping of potentially private data, which can expose secrets in shell history, logs, process listings, or agent traces. In this context, the skill is especially sensitive because it automates access to authenticated web sessions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The login example includes hardcoded credentials and demonstrates automated credential submission to a live URL without any warning about secrets handling, consent, or restricting use to authorized targets. In an agent skill, this normalizes unsafe handling of credentials and could lead users or downstream agents to submit sensitive data to untrusted or phishing pages.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The anti-bot section documents explicit stealth techniques such as disabling automation indicators, spoofing a user agent, removing the webdriver property, and using '--no-sandbox'. In a browser-automation skill, these examples can directly enable bypass of site protections and reduce platform trust boundaries, especially because the stated purpose does not require evasion behavior.

Content

No source excerpt is available for this finding.

Context Window Stuffing

Medium
Category
Memory Poisoning
Confidence
85% confidence
Finding

Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.

Content

Scanner excerpt · SKILL.md (reported line 83)May include surrounding context.

md
browser.py content <url>             # Get full HTML
  browser.py text <url> <selector>     # Get element text
  browser.py click <selector>          # Click element on current page
  browser.py fill <selector> <value>   # Fill input on current page
  browser.py eval <js>                # Run JS on current page
  browser.py extract <url> <selector>  # Extract structured data from page
"""

Context Window Stuffing

Medium
Category
Memory Poisoning
Confidence
85% confidence
Finding

Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.

Content

Scanner excerpt · scripts/cdp.py (reported line 12)May include surrounding context.

python
browser.py content <url>             # Get full HTML
  browser.py text <url> <selector>     # Get element text
  browser.py click <selector>          # Click element on current page
  browser.py fill <selector> <value>   # Fill input on current page
  browser.py eval <js>                # Run JS on current page
  browser.py extract <url> <selector>  # Extract structured data from page
"""

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This code saves a screenshot to an arbitrary filesystem path, which is a file-write operation affecting local user/system data. The file contains no confirmation prompt, disclosure print, or warning near the operation indicating that invoking the command will create or overwrite a file.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The click command can activate arbitrary page elements on live sites, including logout, purchase, consent, deletion, or other state-changing actions. In an agent workflow, untrusted prompts or page content could steer the automation into performing unintended authenticated actions without any confirmation gate.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The fill command allows arbitrary input into forms on live websites, which can alter application state, submit sensitive data, or prepare the page for harmful follow-on actions. In a browser-agent context this increases the risk of prompt-driven abuse, especially when combined with click automation on authenticated sessions.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The eval command exposes arbitrary JavaScript execution in a real browser context, which is broader than the stated purpose of navigation and interaction. In an agent setting, this can be used to run attacker-supplied scripts against arbitrary pages, access DOM-visible sensitive data, trigger authenticated actions, or bypass higher-level safety controls that only expect bounded browser operations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

This Python code makes a network request to an arbitrary URL and captures the rendered page content for output. Although the script name and docstring describe scraping, there is no explicit user-facing warning, confirmation, or privacy notice that remote content will be fetched and returned, which is relevant for operations that transmit user-supplied targets over the network.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This code performs two safety-relevant actions: it makes an outbound request to the provided URL via page.goto(...) and writes a screenshot file to disk via page.screenshot(...). Although the module docstring describes usage, it does not clearly warn that visiting the URL may transmit system/network metadata to a remote site or that a file will be created at the specified path.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The download example writes remotely sourced content directly to a caller-provided path without documenting that untrusted data is being persisted locally. While the snippet is simple documentation, omission of safety guidance can lead to unsafe file placement, accidental overwrites, or retention of sensitive or malicious content on disk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The screenshot example saves page content to local files but does not warn that screenshots may capture sensitive information such as account data, tokens visible in UI, or proprietary content. In an automation skill, this can unintentionally encourage persistent local storage of sensitive material without access-control or retention guidance.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script accepts an arbitrary URL and causes a headless browser to fetch and render it, which can be abused as a server-side request primitive against internal services, cloud metadata endpoints, or otherwise restricted network locations. In the context of a browser-automation skill, this is more dangerous than a normal scraper because Playwright executes page logic and follows modern web flows, increasing SSRF and unintended data-exfiltration risk from untrusted destinations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.