Back to skill

Security audit

browser-file-upload

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward browser file-upload helper, but users should verify the file and website before using it.

Install only if you need browser upload automation. Before running it, confirm the destination domain is trusted and the selected file does not contain secrets, credentials, private workspace data, or other sensitive content. Prefer explicit CSS selectors such as input[type=file] when possible, and note that the bundled Python script appears to have a syntax issue from unescaped Windows paths in its docstring, so direct agent-browser commands may be more reliable until fixed.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (5)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly automates uploading local files to arbitrary external websites and provides concrete examples using local workspace files, but it does not warn about sensitive data exposure, destination trust, or the risk of sending private files off-host. In an agent setting, this increases the chance of unintentional exfiltration because users may treat uploads as routine automation rather than a security-sensitive action.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The fallback element search uses the literal text "选择文件", which assumes the target page is presented in Chinese. This creates a language/locale policy issue because the skill does not offer any user choice or document that it is limited to Chinese-language pages.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The skill examples instruct matching UI text using Chinese strings such as "选择文件" and later "上传文件"/"上传", which bakes in a specific locale assumption. There is no opt-in, alternative language guidance, or note that these labels vary by site locale.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This example uses the Chinese label "上传文件" as if it were generally applicable, which can violate language/locale policy by hard-coding a specific language. The document does not explain that users should adapt text queries based on the site's language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The troubleshooting section recommends agent-browser find text 选择文件 click, again assuming a Chinese-language interface. Without an opt-in or locale note, this is a language-specific instruction presented as a default workflow.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.