Back to skill

Security audit

web-session-miner

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed browser-session scraper, but it repeatedly promotes using logged-in paid web access to avoid official API charges and has weak scoping for sensitive automated collection.

Review before installing. Use only on sites and accounts where you have explicit permission for automated collection, prefer official APIs where required by contract or site terms, avoid personal or high-privilege browser profiles, and do not use it to replace paid programmatic access or scrape member-only data at scale without authorization.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (12)

Intent-Code Divergence

Medium
Confidence
97% confidence
Finding
The README explicitly promotes using a logged-in browser session to obtain data from the web interface while avoiding official per-call API billing, which materially conflicts with later compliance language. That creates a clear misuse path: the skill facilitates session-backed scraping of paid content and normalizes bypassing provider monetization and access controls, increasing legal, account, and data-exposure risk.

Context-Inappropriate Capability

High
Confidence
99% confidence
Finding
The skill explicitly markets reusing an authenticated browser session to avoid official API/MCP usage charges, which encourages unauthorized circumvention of a provider's intended access and billing model. In context, this is not framed as incidental browser automation but as a primary value proposition, increasing the likelihood of misuse against paid data services.

Intent-Code Divergence

High
Confidence
97% confidence
Finding
The compliance section claims the tool is not for bypassing paywalls, but the rest of the document repeatedly advertises using logged-in web sessions to avoid API charges. This contradiction weakens safeguards, creates plausible deniability, and still operationally enables extraction of member-only data in ways likely inconsistent with site terms or licensing.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger phrases are broad business-language prompts such as checking companies, shareholders, controllers, and bulk collection, without narrow gating on authorization, allowed sites, or data sensitivity. In an agent setting, this can cause the skill to activate for ambiguous requests and initiate browser-session-backed collection against third-party sites using an already logged-in account.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The description emphasizes reusing an authenticated browser session as a feature but does not clearly warn that this exposes sensitive account cookies, member-visible data, and potentially personal or corporate information to automated collection flows. In this context, session reuse is especially dangerous because the skill is designed to mine privileged web data at scale, so inadequate warnings can lead users to over-collect or unintentionally expose regulated or confidential information.

Natural-Language Policy Violations

High
Confidence
99% confidence
Finding
Promoting API-billing avoidance as a skill benefit incentivizes use of authenticated browser automation to defeat a service's intended monetization and access controls. In this skill, that messaging is central rather than incidental, making the dangerous purpose explicit and increasing abuse risk.

Natural-Language Policy Violations

High
Confidence
99% confidence
Finding
This section repeatedly encourages avoiding paid API usage by leveraging web-session scraping, normalizing programmatic extraction from authenticated pages as a substitute for official access channels. That creates a clear misuse pathway for acquiring protected commercial data outside intended billing and governance mechanisms.

Natural-Language Policy Violations

High
Confidence
98% confidence
Finding
The core positioning characterizes API-cost avoidance as a principal benefit, which turns the skill into a tool for systematic circumvention rather than ordinary user assistance. Because the document generalizes this method to many target sites, the potential for repeatable abuse across multiple services is substantial.

Natural-Language Policy Violations

Medium
Confidence
90% confidence
Finding
Comparing browser scraping to official MCP as a 'zero-cost' alternative encourages users to choose the less governed channel specifically to avoid paid access. While framed as a feature comparison, it still steers users toward behavior that may violate terms and bypass platform controls.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The recipe explicitly instructs the operator to obtain and reuse a logged-in Tianyancha VIP browser session via QR-code scan, but it does not warn that this grants the skill access to the user's authenticated account context, paid membership entitlements, and potentially sensitive account-scoped data. In this skill's context, the omission is more dangerous because the stated purpose is to programmatically mine data from a real browser session and even bypass official API billing, which increases privacy, compliance, and account-misuse risk.

Ssd 3

High
Confidence
99% confidence
Finding
The skill instructs reuse of the user's logged-in browser session and cookies to extract member-only web data programmatically, effectively operationalizing authenticated data harvesting. In this context, the use of existing session state is what grants access to protected content, so automating around it materially increases the risk of unauthorized bulk collection and misuse of account-linked privileges.

Ssd 3

High
Confidence
99% confidence
Finding
The workflow explicitly tells the agent to inherit browser cookies and extract full text from authenticated pages for structured output, which is a direct recipe for bulk exfiltration of protected web content. In a skill dedicated to mining member-visible data, this substantially increases the danger because it converts interactive access into scalable automated collection.

Static analysis

No suspicious patterns detected.