T09 · Insecure Skill Coding Practices
- Location
scripts/extract.py:22- Finding
Unrestricted URL Navigation with Chromium Sandbox Disabled
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a functional browser automation skill, but it needs Review because it allows broad web interaction, credential entry, local file writes, and unsandboxed arbitrary navigation without enough safeguards.
Install only if you are comfortable reviewing and sandboxing browser automation. Run it as an unprivileged user in an isolated environment with restricted network access, avoid passing passwords or secrets on the command line, do not use it for purchases, account changes, or authenticated workflows without explicit confirmation, and pin the Playwright/browser versions before use.
scripts/extract.py:22Unrestricted URL Navigation with Chromium Sandbox Disabled
SKILL.md:115Sensitive Form Values Are Passed Through Process Arguments and Returned in Output
SKILL.md:146Unpinned Playwright and Chromium Installation Without Integrity Verification
scripts/screenshot.py:25Caller-Controlled Screenshot Path Allows Arbitrary Writable-File Overwrite
The declared description presents this skill as a general browser automation/interactivity tool for JS-rendered pages, emphasizing user interaction and screenshots as the reasons to use it. The supplied code does not implement browser interaction flows or screenshot capture. Instead, its concrete and primary function is targeted data extraction from page elements using a CSS selector. While Playwright is used and the page may be JS-rendered, the code's actual purpose aligns more with extraction/scraping than an interactive browser last-resort tool. This is a material description-behavior mismatch.
The skill documents shell-executable scripts but does not declare any tool scope such as allowed tools or permissions. In an agent environment, missing scope boundaries can let the skill invoke broader shell capabilities than intended, increasing the chance of misuse, unsafe command execution, or policy bypass. Because this skill is explicitly a last-resort browser automation layer that launches scripts, the absence of explicit restrictions is more dangerous than in a purely informational skill.
The documentation instructs users to perform click and fill actions, including login-style workflows, without warning that these actions can change remote state, submit forms, trigger purchases, send messages, or alter accounts. In a browser automation skill, omission of these warnings is dangerous because operators may treat the tool as read-only when it is actually capable of write-side effects on third-party services.
The example login flow includes entering credentials and scraping a dashboard without any guidance on secret handling, consent, storage, or privacy boundaries. This normalizes passing sensitive credentials through command arguments and encourages authenticated scraping of potentially private data, which can expose secrets in shell history, logs, process listings, or agent traces. In this context, the skill is especially sensitive because it automates access to authenticated web sessions.
The login example includes hardcoded credentials and demonstrates automated credential submission to a live URL without any warning about secrets handling, consent, or restricting use to authorized targets. In an agent skill, this normalizes unsafe handling of credentials and could lead users or downstream agents to submit sensitive data to untrusted or phishing pages.
The anti-bot section documents explicit stealth techniques such as disabling automation indicators, spoofing a user agent, removing the webdriver property, and using '--no-sandbox'. In a browser-automation skill, these examples can directly enable bypass of site protections and reduce platform trust boundaries, especially because the stated purpose does not require evasion behavior.
Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.
browser.py content <url> # Get full HTML
browser.py text <url> <selector> # Get element text
browser.py click <selector> # Click element on current page
browser.py fill <selector> <value> # Fill input on current page
browser.py eval <js> # Run JS on current page
browser.py extract <url> <selector> # Extract structured data from page
"""
Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.
browser.py content <url> # Get full HTML
browser.py text <url> <selector> # Get element text
browser.py click <selector> # Click element on current page
browser.py fill <selector> <value> # Fill input on current page
browser.py eval <js> # Run JS on current page
browser.py extract <url> <selector> # Extract structured data from page
"""
This code saves a screenshot to an arbitrary filesystem path, which is a file-write operation affecting local user/system data. The file contains no confirmation prompt, disclosure print, or warning near the operation indicating that invoking the command will create or overwrite a file.
The click command can activate arbitrary page elements on live sites, including logout, purchase, consent, deletion, or other state-changing actions. In an agent workflow, untrusted prompts or page content could steer the automation into performing unintended authenticated actions without any confirmation gate.
The fill command allows arbitrary input into forms on live websites, which can alter application state, submit sensitive data, or prepare the page for harmful follow-on actions. In a browser-agent context this increases the risk of prompt-driven abuse, especially when combined with click automation on authenticated sessions.
The eval command exposes arbitrary JavaScript execution in a real browser context, which is broader than the stated purpose of navigation and interaction. In an agent setting, this can be used to run attacker-supplied scripts against arbitrary pages, access DOM-visible sensitive data, trigger authenticated actions, or bypass higher-level safety controls that only expect bounded browser operations.
This Python code makes a network request to an arbitrary URL and captures the rendered page content for output. Although the script name and docstring describe scraping, there is no explicit user-facing warning, confirmation, or privacy notice that remote content will be fetched and returned, which is relevant for operations that transmit user-supplied targets over the network.
This code performs two safety-relevant actions: it makes an outbound request to the provided URL via page.goto(...) and writes a screenshot file to disk via page.screenshot(...). Although the module docstring describes usage, it does not clearly warn that visiting the URL may transmit system/network metadata to a remote site or that a file will be created at the specified path.
The download example writes remotely sourced content directly to a caller-provided path without documenting that untrusted data is being persisted locally. While the snippet is simple documentation, omission of safety guidance can lead to unsafe file placement, accidental overwrites, or retention of sensitive or malicious content on disk.
The screenshot example saves page content to local files but does not warn that screenshots may capture sensitive information such as account data, tokens visible in UI, or proprietary content. In an automation skill, this can unintentionally encourage persistent local storage of sensitive material without access-control or retention guidance.
The script accepts an arbitrary URL and causes a headless browser to fetch and render it, which can be abused as a server-side request primitive against internal services, cloud metadata endpoints, or otherwise restricted network locations. In the context of a browser-automation skill, this is more dangerous than a normal scraper because Playwright executes page logic and follows modern web flows, increasing SSRF and unintended data-exfiltration risk from untrusted destinations.
No suspicious patterns detected.