Back to skill

Security audit

Playwright Scraper Skill

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed web-scraping skill, but its stealth mode weakens browser protections and gives broad scraping and file-saving power without enough safeguards.

Install only if you need this exact scraping capability and can run it in an isolated environment. Use it only on sites you are authorized to access, avoid authenticated or sensitive pages, keep screenshot/HTML outputs in a dedicated directory, and do not follow the optional deep-scraper install path unless you separately review and pin that dependency.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/playwright-simple.js:11
Finding

Unrestricted Browser Navigation Enables Server-Side Request Forgery

Content
View full analysis
'); process.exit(1); } (async () => { console.log('🚀 啟動 Playwright 簡單版爬蟲...'); const startTime = Date.now(); const browser = await chromium.launch({ headless: process.env.HEADLESS !== 'false' }); const page = await browser.newPage(); console.log(`📱 導航到: ${url}`); await page.goto(url, { waitUntil: 'domcontentloaded' }); ``` `scripts/playwright-stealth.js:22-22, 87-90`: ```js const url = process.argv[2]; ``` ```js const response = await page.goto(url, { waitUntil: 'domcontentloaded', timeout: 30000, }); ``` ### Technical Analysis Both scraper modes pass a caller-controlled URL directly to Playwright without validating its scheme, hostname, resolved IP address, port, or redirect destinations. The implementation does not block loopback, link-local, private, reserved, or cloud metadata addresses. Because Chromium makes the request from the machine running the Skill, the target is reached with the Agent host's network access rather than the external requester's access. The scripts subsequently extract page text and print it to standard output. This creates a practical SSRF primitive against HTTP services accessible from the host. Protocol validation is also absent. At minimum, navigation should be restricted to explicitly approved `http:` and `https:` destinations. Redirects must be validated separately because an initially public URL can redirect to an int ...[truncated 1174 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/playwright-stealth.js:43
Finding

Chromium Security Sandbox Is Explicitly Disabled

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/playwright-stealth.js:124
Finding

Unrestricted Output Paths Permit Overwriting Files Accessible to the Agent

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:87
Finding

Instructions Install and Execute an Unpinned External Skill

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (35)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The documentation claims anti-bot and stealth capabilities for protected sites, which can mislead users and downstream agents about what the skill actually does. Security-relevant misrepresentation is dangerous because operators may rely on the skill in higher-risk contexts, disable safeguards, or mis-handle blocked or sensitive targets under false assumptions.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 20)May include surrounding context.

md
| **Cloudflare Protected** | High | **Playwright Stealth** ⭐ | `scripts/playwright-stealth.js` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 74)May include surrounding context.

md
| **Cloudflare Protected** | High | **Playwright Stealth** ⭐ | `scripts/playwright-stealth.js` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 108)May include surrounding context.

md
| **Cloudflare Protected** | High | **Playwright Stealth** ⭐ | `scripts/playwright-stealth.js` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 126)May include surrounding context.

md
| **Cloudflare Protected** | High | **Playwright Stealth** ⭐ | `scripts/playwright-stealth.js` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 141)May include surrounding context.

md
| **Cloudflare Protected** | High | **Playwright Stealth** ⭐ | `scripts/playwright-stealth.js` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 147)May include surrounding context.

md
| **Cloudflare Protected** | High | **Playwright Stealth** ⭐ | `scripts/playwright-stealth.js` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 150)May include surrounding context.

md
| **Cloudflare Protected** | High | **Playwright Stealth** ⭐ | `scripts/playwright-stealth.js` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 153)May include surrounding context.

md
| **Cloudflare Protected** | High | **Playwright Stealth** ⭐ | `scripts/playwright-stealth.js` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 192)May include surrounding context.

md
| **Cloudflare Protected** | High | **Playwright Stealth** ⭐ | `scripts/playwright-stealth.js` |

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · test.sh (reported line 43)May include surrounding context.

sh
echo ""

# 清理
rm -f /tmp/test-*.json screenshot-*.png

echo "✅ 所有測試通過!"

Rp1

Medium
Category
MCP Rug Pull
Confidence
81% confidence
Finding

The installation guide instructs users to run npx playwright install chromium without pinning a specific Playwright version. npx can resolve and execute package code based on the current environment or registry state, so an unpinned invocation reduces reproducibility and increases supply-chain risk if a compromised or unexpected version is fetched.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
81% confidence
Finding

This command again relies on npx playwright without a pinned version, which means users may execute whatever version is currently resolved from dependencies or the package registry. In an installation document, that creates a supply-chain exposure and can lead to inconsistent behavior across environments.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
81% confidence
Finding

The documentation repeats an unpinned npx playwright invocation, exposing users to unintended package resolution and potential registry-based tampering. While common in developer docs, it still represents a real dependency-integrity weakness because execution is not tied to a vetted version.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README explicitly promotes anti-bot evasion techniques such as hiding navigator.webdriver, using realistic user agents, and simulating human behavior, while also advertising screenshot/HTML saving. In a scraping skill, that combination increases the likelihood of bypassing site restrictions and collecting content or personal data without informed warnings about legal, terms-of-service, or privacy implications, making misuse materially more likely.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README explicitly promotes stealth scraping, anti-bot evasion, screenshot capture, and HTML saving, but does not warn about legal restrictions, privacy risks, or safe handling of captured content. In a scraping skill, this omission increases the likelihood that operators will collect protected or personal data, bypass site defenses, and retain sensitive page contents without understanding the consequences.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill documents use of environment variables and executable scripts but declares no explicit tool scope or permissions boundary. In an agent ecosystem, missing scope declarations can lead to over-broad execution or unclear trust assumptions, making it easier for the skill to access capabilities users did not expect.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

Using npx playwright without pinning a version creates a supply-chain risk because the installed package may change over time or resolve to a compromised release. This makes builds non-reproducible and can introduce unexpected code execution during installation or runtime.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill promotes stealth scraping, screenshot capture, and HTML saving without warning that these actions may collect personal data, session artifacts, or copyrighted/private content. In practice, saved screenshots and raw HTML can retain tokens, user identifiers, and sensitive page content, increasing privacy and data-retention risk.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

Using npx clawhub install deep-scraper without a pinned version allows arbitrary future package changes to be pulled at install time. Because this installs and executes third-party skill code, it expands supply-chain exposure beyond the current skill and could lead to execution of malicious or tampered dependencies.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.