Back to skill

Security audit

Agent Browser Xiaoshu

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed browser-automation skill, but users should protect any saved browser sessions and captured page artifacts.

Install only if you trust the upstream agent-browser CLI. Use it with dedicated low-privilege browser sessions when possible, avoid saving state for highly sensitive accounts, and treat auth.json, screenshots, PDFs, traces, and recordings as sensitive files that may contain cookies, tokens, passwords, or private page content.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill explicitly documents saving and loading authenticated browser state without warning that session files can contain cookies, tokens, and other sensitive authentication artifacts. In an agent context, this can normalize insecure handling of credential-bearing files and lead to unintended persistence, reuse, or exfiltration of authenticated sessions.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal