Back to skill

Security audit

Chrome Control Proxy

Security checks for vulnerabilities and agentic risk

Overview

The skill is a disclosed browser-control guide, but it asks users to globally install an unpinned package and exposes powerful Playwright browser scripting that deserves review before use.

Install only if you trust the npm package and publisher. Prefer a pinned reviewed version, run the service bound to localhost only, avoid exposing /playwright/run to other users or networks, and consider using a separate browser profile without sensitive logged-in sessions.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:22
Finding

Unpinned Global Installation of a Third-Party npm Package

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 22
Vulnerability Type: Unpinned and globally installed third-party dependency
Risk Level: Medium

Vulnerable Code Snippet:

markdown
1. The host must have **Node ≥ 18** installed, and the service package must be installed globally: `npm install -g chrome-control-proxy`.

Technical Analysis

The Skill directs users to install chrome-control-proxy globally from the configured npm registry without specifying an exact package version, verifying package integrity, providing a lockfile, or including the dependency's implementation in the audited project.

Consequently, the code installed when this instruction is followed can differ from the code available when the Skill was reviewed. npm installation may also execute package lifecycle scripts, such as preinstall, install, and postinstall, with the privileges of the user running the command. The global installation scope places package executables in shared system or user-level npm locations, increasing the potential effect of a compromised release.

The reviewed file does not establish that the package is malicious. The vulnerability is the unsafe supply-chain boundary created by retrieving and globally installing a mutable, unaudited dependency.

Attack Path

  1. An attacker compromises the npm publisher account, package repository, release pipeline, or another component of the package's distribution chain.
  2. The attacker publishes a malicious release under the legitimate chrome-control-proxy package name.
  3. A user follows the Skill's unpinned command, causing npm to resolve and download the currently selected release.
  4. npm installs the package globally and may execute attacker-controlled lifecycle scripts.
  5. Malicious code runs with the invoking user's privileges or is later executed through the globally installed ccp command.
  6. Because the package controls a browser automation ...[truncated 874 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the dependency to a reviewed exact version instead of resolving the latest compatible release:
    bash
    npm install -g chrome-control-proxy@<audited-exact-version>
    
  2. Document the expected package version and integrity digest, and verify the downloaded package archive before installation.
  3. Prefer a project-local installation with a committed lockfile over global installation:
    bash
    npm install --save-exact chrome-control-proxy@<audited-exact-version>
    
  4. Review the package source, transitive dependencies, published archive, and lifecycle scripts for the pinned release.
  5. Where compatible with the package's installation requirements, disable lifecycle scripts using --ignore-scripts; otherwise, explicitly audit every required lifecycle script.
  6. Use an approved registry, registry allowlisting, provenance verification, and continuous dependency monitoring.
  7. Run the service as a dedicated, unprivileged user and restrict its filesystem, network, browser-profile, and credential access.
  8. Bind the browser-control service only to a trusted local interface and require authentication or equivalent access controls if it can be reached across a network boundary.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

The description and heading are written entirely in Chinese, and the file does not indicate that language selection is optional or that the skill is intentionally limited to Chinese-speaking users. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.