Back to skill

Security audit

web-access-openclaw

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent browser automation, but it exposes a long-lived unauthenticated local proxy with broad control over logged-in Chrome sessions and insufficient safeguards.

Install only if you specifically need an agent to operate your real logged-in Chrome. Do not use it for routine searches, and avoid running it while sensitive tabs are open. Treat file uploads, form submissions, posting, deleting, purchasing, and screenshot saving as actions requiring explicit review. Stop the proxy when finished and avoid sending private, internal, signed, or token-bearing URLs to third-party preprocessors such as Jina.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (5)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/cdp-proxy.mjs:261
Finding

Unauthenticated Local API Exposes Full Control of Authenticated Chrome Sessions

Content
View full analysis
{ const parsed = new URL(req.url, `http://localhost:${PORT}`); const pathname = parsed.pathname; const q = Object.fromEntries(parsed.searchParams); res.setHeader('Content-Type', 'application/json; charset=utf-8'); try { // /health does not require a Chrome connection if (pathname === '/health') { const connected = ws && (ws.readyState === WS.OPEN || ws.readyState === 1); res.end(JSON.stringify({ status: 'ok', connected, sessions: sessions.size, chromePort })); return; } await connect(); ``` ```js // GET /targets - list all pages if (pathname === '/targets') { const resp = await sendCDP('Target.getTargets'); const pages = resp.result.targetInfos.filter(t => t.type === 'page'); res.end(JSON.stringify(pages, null, 2)); } ``` ```js // POST /eval?target=xxx - execute JavaScript else if (pathname === '/eval') { const sid = await ensureSession(q.target); const body = await readBody(req); const expr = body || q.expr || 'document.title'; const resp = await sendCDP('Runtime.evaluate', { expression: expr, returnByValue: true, awaitPromise: true, }, sid); if (resp.result?.result?.value !== undefined) { res.end(JSON.stringify({ value: resp.result.result.value })); } else if (resp.result?.exceptionDetails) { res.statusCode = 400; res.end(JSON.stringify({ error: resp.result.exceptionDetails.text })); } else { res.end(JSON.stringify(resp.result)); } } ``` ```js else if (pathname === '/setFiles') { const sid = await ensureSession(q.target); const body = JSON.parse(await readBody(req)); if (!body.selector || !body.files) { res.statusCode = 400; r ...[truncated 3437 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/cdp-proxy.mjs:478
Finding

Caller-Controlled Screenshot Path Permits Arbitrary File Overwrite

Content
View full analysis
&file=`. 5. `fs.writeFileSync` truncates and replaces the selected file with screenshot bytes. 6. The affected ap ...[truncated 763 chars]
Remediation
View remediation

other

Warning
Location
SKILL.md:56
Finding

Instructions Can Disclose Token-Bearing URLs to a Third-Party Processing Service

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/check-deps.mjs:94
Finding

Detached Privileged Proxy Remains Active Beyond the Invoking Task

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
scripts/cdp-proxy.mjs:19
Finding

Legacy Runtime Fallback Relies on an Unpinned Global Dependency

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (22)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill relies on attaching to the user's existing Chrome session, inheriting cookies, authentication, and browsing context, but does not prominently warn about that in the description/trigger area. This creates a substantial risk of agents accessing or acting within sensitive logged-in accounts without sufficiently informed user consent.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The /eval endpoint accepts arbitrary JavaScript and executes it inside the user's live Chrome session via Runtime.evaluate. Because this proxy attaches to existing browser targets, the code can read page contents, cookies-accessible data, DOM state, and interact with authenticated sessions well beyond the declared 'web-access' purpose, creating a powerful capability for data theft or unauthorized actions.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The /setFiles endpoint can inject arbitrary local filesystem paths into file inputs in web pages using DOM.setFileInputFiles. This lets the skill exfiltrate local files through the browser to remote sites without meaningful user confirmation, which is especially dangerous in a logged-in real-browser context where uploads may immediately transmit sensitive data.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The file upload manipulation endpoint performs a highly sensitive action without any user-facing warning, confirmation, or provenance check. In the context of controlling the user's daily Chrome, silent uploads can leak private local documents to arbitrary websites, making the missing consent flow a serious security issue rather than a mere UX gap.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill exposes powerful capabilities (environment access, network operations, local script execution, and browser automation) without declaring a restrictive tool scope. That increases the chance an agent loads and uses the skill more broadly than intended, especially because the skill is framed as mandatory for all networking tasks.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger scope is extremely broad, effectively claiming all network-related tasks including search, browsing, login-based actions, dynamic pages, and social platforms. Over-broad triggering increases the odds this high-privilege skill is invoked unnecessarily, expanding exposure to logged-in browser state and local side effects.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
87% confidence
Finding

The skill recommends sending target URLs through Jina, a third-party service that transforms web pages into Markdown. That can transmit user-requested destinations and potentially sensitive page-derived content to an external service without an explicit warning, which is especially risky when the skill may be used on private or sensitive targets.

Content

Scanner excerpt · SKILL.md (reported line 54)May include surrounding context.

md
| 非公开内容,或已知静态层无效的平台(小红书、微信公众号等公开内容也被反爬限制) | **浏览器 CDP**(直接,跳过静态层) |
| 需要登录态、交互操作,或需要像人一样在浏览器内自由导航探索 | **浏览器 CDP** |

浏览器 CDP 不要求 URL 已知——可从任意入口出发,通过页面内搜索、点击、跳转等方式找到目标内容。WebSearch、WebFetch、curl 均不处理登录态。

**Jina**(可选预处理层,可与 WebFetch/curl 组合使用,由于其特性可节省 tokens 消耗,请积极在任务合适时组合使用):第三方网络服务,可将网页转为 Markdown,大幅节省 token 但可能有信息损耗。调用方式为 `r.jina.ai/example.com`(URL 前加前缀,不保留原网址 http 前缀),限 20 RPM。适合文章、博客、文档、PDF 等以正文为核心的页面;对数据面板、商品页等非文章结构页面可能提取到错误区块。

Ssd 2

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The guidance explicitly recommends choosing interaction styles that appear more like normal user behavior when programmatic methods are blocked, in order to avoid anti-bot restrictions. That meaningfully steers the agent toward bypassing website protective controls rather than respecting access boundaries.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill omits clear warnings that screenshots are written to local disk and that site-pattern data may be stored locally. Silent file writes can surprise users, leak sensitive page content into persistent storage, and expand the skill's impact beyond transient browsing.

Content

No source excerpt is available for this finding.

Ssd 2

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill advises preserving full session-related parameters and treating 'content not found' style responses as possibly deceptive artifacts of blocked access. In context, this encourages the agent to work around access restrictions and continue probing for successful retrieval rather than treating failures as enforcement boundaries.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill instructs the agent to persist site-specific knowledge by writing local reference files, which creates durable state unrelated to simply performing web access for the current task. Persistent writes can capture sensitive browsing-derived information, accumulate unsafe assumptions, and modify the local environment without a clear user request.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The entire reference is written only in Chinese, with no indication that language is selectable or that the locale restriction is intentional and justified. Per the policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/cdp-api.md (reported line 15)May include surrounding context.

GET /health

健康检查,返回连接状态。

bash
curl -s http://localhost:3456/health

GET /targets

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The document describes an API that can set arbitrary local files into a browser file input and upload them to whatever site is open, but it does not warn about the data exfiltration risk. In a web-access skill, this materially increases the chance that an agent or operator will transmit sensitive local files to remote services without explicit user consent or path restrictions.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The inline comment for /clickAt explicitly advertises that the browser-level click can 'count as a user gesture' and 'bypass anti-automation detection.' That framing indicates the feature is intended to defeat website safety or anti-bot controls, increasing the risk that the proxy will be used to perform actions sites deliberately try to restrict or gate behind real user interaction.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The /screenshot endpoint can write captured image data to any caller-supplied local path using fs.writeFileSync(q.file,...). This exceeds the declared browser/network scope and introduces arbitrary local file write behavior, which can overwrite user files or place sensitive screenshots in unexpected locations on disk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

Saving screenshots to disk without an explicit warning or confirmation can persist sensitive page contents, including authenticated account data, in locations the user did not intend. Because the proxy operates against the user's real browser session, screenshots may capture secrets from internal tools, email, or social platforms and silently leave forensic artifacts on disk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code file contains natural-language instructions and status text in Chinese, beginning with the header comment and continuing throughout the script. Because the skill forces a specific language for operational guidance without any opt-in or alternative, it creates a locale-policy issue for users who do not read Chinese.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script's runtime prompts about authorization and setup are safety-relevant operational instructions, but they are only shown in Chinese. This forces a specific language during execution and may prevent some users from understanding required actions or warnings.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The skill claims minimal intrusion into the user's environment while elsewhere directing persistent local file modifications. That mismatch can mislead users or agents about the real side effects, reducing informed consent and making unexpected persistence more likely.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The screenshot endpoint can write arbitrary image output to a local filesystem path, but the documentation omits any warning about local file write side effects. While less severe than exfiltration, undocumented file creation can overwrite files, leak captured sensitive page content into local storage, or enable unsafe automation practices.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The file's user-facing comments and operational messages are written in Chinese, with no indication of language choice or opt-in. This can violate language or locale policy when a skill implicitly forces a specific language for usage and troubleshooting.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec, suspicious.env_credential_access

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/check-deps.mjs:98

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/check-deps.mjs:13