Back to skill

Security audit

Claw Browser Automation

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent browser-automation wrapper, but users should handle saved sessions, cookies, recordings, and the unpinned npm install carefully.

Install in a least-privilege or disposable environment where possible, pin and verify the agent-browser package before use, and avoid elevated installs unless you understand the dependency changes. Use the browser commands only on sites and accounts you are authorized to automate. Treat auth.json, cookies, localStorage output, screenshots, PDFs, traces, videos, request logs, and CDP-connected sessions as sensitive, and delete or protect those files after the task.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:17
Finding

Unpinned Global Installation of Executable Third-Party Dependency

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 17–19
Vulnerability Type: Unpinned executable dependency obtained from a mutable package registry
Risk Level: Medium

Complete Code Snippet:

bash
npm install -g agent-browser
agent-browser install
agent-browser install --with-deps

Technical Analysis

The installation procedure retrieves agent-browser from the npm registry without specifying an exact version or verifying an integrity hash. Consequently, the installed artifact can change after this Skill has been reviewed.

npm installation may execute package lifecycle scripts, while the subsequent agent-browser install commands execute code supplied by the downloaded package. The --with-deps option may additionally install or modify system-level dependencies. None of that executable dependency code is included in this project and therefore could not be inspected during this audit.

Global installation increases exposure by placing the package in a shared environment rather than isolating it to this project. This is a supply-chain weakness; the audited files do not establish that the current upstream package is malicious.

Attack Path

  1. An attacker compromises the npm package maintainer account, package publication workflow, registry distribution path, or a transitive dependency.
  2. The attacker publishes a malicious package version under the default npm distribution tag.
  3. A user follows the documented npm install -g agent-browser command.
  4. npm retrieves the attacker-controlled release and may execute its lifecycle scripts with the invoking user's privileges.
  5. The user then runs agent-browser install or agent-browser install --with-deps, providing another execution opportunity and potentially permitting broader system changes.
  6. The malicious package can act within the permissions available to the invoking process.

Impact Assessment

Successful exploitati ...[truncated 563 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin agent-browser to an exact version that has been independently reviewed; do not use an omitted version or a mutable distribution tag.
  2. Prefer a project-local dependency governed by a committed lockfile over global installation.
  3. Verify package provenance and integrity through npm integrity metadata, signed provenance where available, and a documented expected publisher and registry.
  4. Audit npm lifecycle scripts and the implementation of both installer commands before recommending execution.
  5. Run installation in a sandbox, container, or disposable least-privilege environment without production credentials.
  6. Avoid elevated privileges. If operating-system packages are necessary, enumerate and pin them explicitly rather than delegating unrestricted installation to a downloaded CLI.
  7. Establish an update-review process so a version change requires security review before documentation is updated.

T08 · Insecure Dependencies

Warning
Location
CONTRIBUTING.md:17
Finding

Explicit Use of Mutable Latest Tag for Global Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: CONTRIBUTING.md, lines 17–20
Vulnerability Type: Mutable latest-version installation of executable third-party code
Risk Level: Medium

Complete Code Snippet:

markdown
1. Install the latest version
   ```bash
   npm install -g agent-browser@latest
   ```

Technical Analysis

The contribution instructions explicitly install agent-browser@latest. The latest npm distribution tag is mutable and can resolve to a different artifact over time without any corresponding modification to this audited project.

A global npm installation may execute lifecycle scripts from the package and its dependency graph. Because neither a fixed version nor an integrity value is supplied, users cannot reliably reproduce the reviewed installation or ensure that future executions obtain an identical artifact.

This finding represents unsafe dependency acquisition rather than evidence that the currently published package is malicious.

Attack Path

  1. An attacker gains the ability to publish to agent-browser, compromises its release pipeline, or injects malicious behavior through its dependency chain.
  2. A malicious release is assigned the npm latest tag.
  3. A contributor follows the documented troubleshooting procedure.
  4. npm resolves @latest to the malicious release and installs it globally.
  5. Package lifecycle scripts or later CLI execution runs the attacker-controlled code with the contributor's current privileges.

Impact Assessment

Exploitation could yield arbitrary code execution in the contributor's environment. The attacker could access user-readable source code, files, environment variables, authentication material, and network resources, or alter globally installed tools.

The maximum practical scope depends on the privileges and secrets available to the installation process. System-wide compromise is possible if a user independently executes th ...[truncated 103 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace agent-browser@latest with an exact, reviewed version.
  2. Prefer local installation with a committed lockfile rather than a global package.
  3. Record and verify expected package integrity and provenance.
  4. Add a controlled dependency-update process that reviews release changes before advancing the pinned version.
  5. Recommend testing in an isolated, least-privilege environment with sensitive credentials removed.
  6. Where lifecycle scripts are unnecessary, evaluate installation with scripts disabled; if they are required, audit them before execution.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (7)

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · CONTRIBUTING.md (reported line 60)May include surrounding context.

md
## Adding New Commands to the Skill

Update SKILL.md when the upstream CLI adds new commands.
- Keep the Installation section
- Add new commands in the correct category
- Include usage examples

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest describes the skill as browser automation but does not clearly disclose that it can persist and replay authenticated state, modify cookies/storage, set credentials, and write artifacts such as auth state files, traces, screenshots, and videos. That mismatch can cause an agent or operator to invoke the skill with a lower perceived risk than warranted, increasing the chance of accidental sensitive-data exposure or unauthorized session reuse.

Content

No source excerpt is available for this finding.

Context Window Stuffing

Medium
Category
Memory Poisoning
Confidence
85% confidence
Finding

Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.

Content

Scanner excerpt · SKILL.md (reported line 41)May include surrounding context.

agent-browser open # Navigate to page agent-browser snapshot -i # Get interactive elements with refs agent-browser click @e1 # Click element by ref agent-browser fill @e2 "text" # Fill input by ref agent-browser close # Close browser

text

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documented commands expose high-value session material: cookies, localStorage, HTTP credentials, custom headers, request logs, and saved browser state, yet the skill provides no privacy or credential-handling warning. In an agent setting, these features can extract secrets from authenticated sessions or persist them to disk for later reuse, creating account takeover and data-leakage risk.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
91% confidence
Finding

The skill explicitly supports saving and loading browser session state, which can include authenticated cookies and storage sufficient to resume logged-in access. In the context of agent-driven browser automation, persisted auth state is particularly sensitive because it enables silent session replay across runs and systems if the file is copied or mishandled.

Content

Scanner excerpt · SKILL.md (reported line 236)May include surrounding context.

bash
agent-browser state save auth.json    # Save session state
agent-browser state load auth.json    # Load saved state

Example: Form submission

Session Persistence

Medium
Category
Rogue Agent
Confidence
95% confidence
Finding

The example workflow normalizes saving login state to 'auth.json' and reloading it later, but it does not caution that the file may function as a bearer artifact for authenticated access. Because it is shown in an authentication example, the dangerousness is elevated: users are more likely to persist real production session material without safeguards.

Content

Scanner excerpt · SKILL.md (reported line 265)May include surrounding context.

agent-browser wait --url "/dashboard" agent-browser state save auth.json

Later sessions: load saved state

agent-browser state load auth.json agent-browser open https://app.example.com/dashboard

text

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill documents multiple file-writing operations—screenshots, PDFs, videos, traces, and auth state files—without warning that these artifacts may contain page contents, tokens, personal data, or debugging information. In practice, operators may leave sensitive artifacts on disk, in repos, or in shared workspaces where they can be exfiltrated later.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.