Back to skill

Security audit

Clawdbot Agent Browser

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent browser-automation guide, but users should handle saved auth state, cookies, and the global install command carefully.

Install from a trusted source, prefer a pinned or project-local agent-browser version, and avoid running system dependency installation with elevated privileges unless needed. Treat saved auth files, cookies, and local storage as credentials: keep them out of repositories and shared workspaces, restrict access, redact them from logs, and delete them when no longer needed.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:195
Finding

Unpinned Global Installation of a Third-Party Browser Automation Package

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 195-199
Vulnerability Type: Unpinned third-party dependency and mutable installation source
Risk Level: Medium

bash
npm install -g agent-browser
agent-browser install                     # Download Chromium
agent-browser install --with-deps         # Linux: + system deps

Technical Analysis

The installation instructions globally install agent-browser without specifying a reviewed version or verifying package integrity. Consequently, the installed code depends on whichever package version the registry serves when the command is executed. The subsequent installation commands also download Chromium and, with --with-deps, may install system-level dependencies without documented artifact verification.

If the package registry account, upstream release process, package contents, or downloaded browser artifacts are compromised, following these instructions could execute attacker-controlled installation or runtime code. A global installation increases exposure because the resulting executable is placed in the user's general command environment rather than being isolated to this project.

The audited files do not themselves contain a malicious payload. Exploitation depends on compromise or unsafe mutation of the external dependency or its distribution channel.

Attack Path

  1. An attacker compromises the package publisher, registry entry, release process, or an artifact downloaded by the installation command.
  2. The attacker publishes a malicious or modified release under the expected package identity.
  3. A user follows the Skill instructions and runs npm install -g agent-browser without a pinned version or integrity check.
  4. The package manager downloads and installs the attacker-controlled release globally.
  5. Package installation hooks or later CLI execution run malicious code with the privileges of the invoking user.
  6. If installation is performed with elevated privileges, ...[truncated 620 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin agent-browser to a specifically reviewed version rather than installing the latest available release:
    bash
    npm install --global agent-browser@<reviewed-version>
    
  2. Record and verify the expected package integrity hash and obtain packages only from the documented official registry and publisher.
  3. Prefer a project-local installation with a lockfile over a global installation, then invoke the binary through the project package manager.
  4. Pin and verify downloaded Chromium artifacts, including their expected version and cryptographic checksum.
  5. Separate system-dependency installation from normal Skill use and require explicit administrator approval before running install --with-deps.
  6. Run the browser tool in a sandbox, container, or dedicated low-privilege account with restricted filesystem and credential access.
  7. Periodically review pinned releases and update them through a controlled dependency-review process rather than accepting automatic upstream changes.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly recommends saving and loading browser auth state to skip login flows, but it does not warn that these files can contain highly sensitive cookies, tokens, and local/session storage. In an agent context, this increases the chance that credentials are persisted insecurely, reused across tasks, or exposed through logs, shared workspaces, or source control.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill documents direct access to cookies and browser storage without any privacy or credential-handling guidance. Because these interfaces can expose session identifiers, CSRF tokens, and other secrets, an agent may retrieve, display, or persist sensitive data in ways that enable account takeover or data leakage.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.