Back to skill

Security audit

DoubaoChatObtain

Security checks for vulnerabilities and agentic risk

Overview

The skill’s goal is coherent, but it needs review because it asks agents to install and run an unpinned browser automation package and uses weak temporary-file handling for extracted conversation data.

Install only after reviewing or pinning the agent-browser dependency, and run it only on Doubao conversations you intentionally want extracted. Choose a private output location, avoid the shared /tmp default for sensitive content, and treat the saved transcript as persistent local data.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:20
Finding

Unpinned Third-Party Browser Automation Package Installation and Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 20-30
Vulnerability Type: Unpinned executable dependency and supply-chain exposure
Risk Level: Medium

Vulnerable Code:

bash
npm install -g agent-browser
# Or install it at project level
npm install agent-browser
bash
npx agent-browser --version

Technical Analysis

The Skill instructs users to install and execute agent-browser without pinning an exact reviewed version, supplying a lockfile, or verifying package integrity. Consequently, the installed implementation may change independently of the audited Skill.

Both global and project-level npm installation execute package-controlled installation logic with the permissions of the invoking user. Subsequent npx agent-browser commands execute the installed package. Depending on npm and npx configuration, npx may also retrieve a missing package from the configured registry.

The browser automation capability is relevant to the declared extraction function, but retrieving an unpinned executable package is broader and less deterministic than necessary. The inspected project does not establish that the resolved package version is the same version reviewed by the Skill author.

Attack Path

  1. An attacker compromises the upstream package, a maintainer account, or the package distribution channel.
  2. A malicious or otherwise unsafe version is published under the expected package name.
  3. A user follows the Skill instructions and runs npm install -g agent-browser, npm install agent-browser, or an npx agent-browser invocation without a verified local installation.
  4. npm retrieves the affected release.
  5. Package lifecycle scripts or the package CLI execute with the user's local permissions.
  6. The malicious package can access resources available to that user, independently of the fixed DOM extraction code shown in the Skill.

Impact Assessment

Successful exp ...[truncated 625 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin agent-browser to an exact, reviewed version rather than relying on the registry's current version.
  2. Add a package manifest and committed lockfile containing integrity metadata.
  3. Install dependencies using a deterministic command such as npm ci.
  4. Invoke only the verified local installation, for example with npx --no-install agent-browser, to prevent implicit downloads.
  5. Review package lifecycle scripts and disable unnecessary scripts during installation where operationally possible.
  6. Document the reviewed package source, exact version, expected integrity hash, and update process.
  7. Run browser automation under a restricted, non-administrative account with access limited to the files required for extraction.

T09 · Insecure Skill Coding Practices

Note
Location
SKILL.md:45
Finding

Predictable Shared Temporary File Permits Symlink and Race Attacks

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 45; scripts/parse_doubao.py, lines 39-40
Vulnerability Type: Unsafe predictable temporary-file handling
Risk Level: Low

Vulnerable Code:

bash
npx agent-browser eval --json "(() => { const c = [...document.querySelectorAll('div')].find(el => { const s = getComputedStyle(el); return (s.overflowY==='auto'||s.overflowY==='scroll') && el.scrollHeight > el.clientHeight; }); return c ? c.innerText : 'NOT_FOUND'; })();" > /tmp/doubao_raw.json
python
parser.add_argument('--input', '-i', default='/tmp/doubao_raw.json',
                    help='agent-browser eval --json output file path')

Technical Analysis

The workflow writes browser output to the fixed path /tmp/doubao_raw.json. Shared temporary directories can be writable by other local users or processes. Shell output redirection opens an existing destination and normally follows symbolic links. The parser then trusts the same predictable path without checking ownership, file type, permissions, or whether the file was replaced between creation and use.

The implementation therefore permits time-of-check/time-of-use races, cross-run collisions, and symbolic-link substitution. Concurrent Skill invocations can also overwrite each other's extraction data.

The parser itself only parses JSON and writes the extracted string; it does not execute content from the temporary file. Therefore, substituted JSON does not directly create code execution through parse_doubao.py.

Attack Path

Symlink overwrite path:

  1. A local attacker predicts that the workflow will use /tmp/doubao_raw.json.
  2. Before the browser command runs, the attacker creates that path as a symbolic link to another file writable by the victim account.
  3. The victim runs the documented command.
  4. Shell redirection follows the symbolic link and truncates or overwrites the linked file with browser JSON ou ...[truncated 1252 chars]
Remediation
View remediation

Remediation Suggestions

  1. Create a unique private temporary directory for every invocation using mktemp -d or Python's tempfile.TemporaryDirectory.
  2. Store the JSON inside that directory and pass its generated path explicitly to the parser.
  3. Set restrictive permissions, such as mode 0700 for the directory and 0600 for the file.
  4. Use exclusive file creation and reject symbolic links or non-regular files.
  5. Keep extraction and parsing within one controlled process where possible, avoiding a shared intermediary pathname.
  6. Remove temporary data in a cleanup handler even when extraction or parsing fails.
  7. If a fixed path must be supported for compatibility, verify file ownership, permissions, and regular-file status before reading it; however, a unique private path remains preferable.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (8)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description says this skill should read full content from a Doubao conversation page itself, specifically solving the virtual-scroll problem via direct DOM/JavaScript extraction. However, the provided code does not interact with a browser, web page, DOM, or Doubao URL at all. It only reads a local JSON file, extracts data.result, and saves it as text. While saving extracted text locally is consistent with part of the description, the primary described capability—page extraction from Doubao via DOM handling—is absent. Therefore the code materially under-implements and misrepresents the declared purpose.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
96% confidence
Finding

The skill performs file-writing behavior by directing output to local paths, but it does not declare any tool scope or permissions boundary. That creates an authorization gap where a caller may invoke a skill that persists potentially sensitive scraped content without an explicit, reviewable permission model.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger condition is broad enough to activate whenever a user shares a Doubao link or asks to read a Doubao page, which increases the chance of unintended invocation. In context, this can lead to automated browsing, DOM extraction, and local persistence of large amounts of page content without a sufficiently specific user request for scraping or saving.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description does not prominently warn that extracted page content will be saved locally, even though it writes potentially sensitive conversation text to disk. This weakens informed consent and increases privacy risk, especially if the page contains personal data, confidential content, or account-scoped material visible only to the current browser session.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

Using npx agent-browser without pinning an exact version introduces supply-chain risk because execution may fetch or resolve an unexpected package version at runtime. If the package is compromised or a breaking version is published, the skill could execute attacker-controlled code in the user's environment.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

This invocation again relies on an unpinned npx agent-browser, which can dynamically resolve code at execution time. That expands the attack surface from the skill itself to the upstream package registry and any dependency compromise affecting the browser automation tool.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

A third unpinned npx agent-browser reference repeats the same supply-chain weakness and normalizes unsafe execution practices in the skill instructions. Because this step executes JavaScript against a live page context, compromise of the tool could lead to code execution and data exposure beyond the intended extraction task.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The docstring usage and purpose text are written only in Chinese, and all runtime messages are also Chinese-only. This creates a natural-language locale constraint without any user opt-in or stated justification that the skill is region-specific.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.