Back to skill

Security audit

Web Scraper Pro Zhuyu28

Security checks for vulnerabilities and agentic risk

Overview

This skill is a minimal browser-automation package, but its form-filling path can expose submitted data in command arguments and output while the documentation lacks safety controls.

Review before installing. Avoid using this skill with passwords, tokens, personal data, payment information, or authenticated workflows unless it is revised to redact form values, avoid command-line secret handling, and require explicit confirmation for state-changing actions.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/scrape_web.py:43
Finding

Plaintext Exposure of Sensitive Form Data Through Process Arguments and Standard Output

Content
View full analysis

Vulnerability Details

File Location: scripts/scrape_web.py, lines 43-48 and 76-78
Vulnerability Type: Plaintext sensitive-data exposure
Risk Level: Medium

Vulnerable Code

python
results = {
    "url": url,
    "form_data": form_data,
    "status": "submitted",
    "response": "Form submitted successfully"
}
python
url = sys.argv[2]
form_data = json.loads(sys.argv[3])
result = fill_form(url, form_data)
print(json.dumps(result, indent=2))

Technical Analysis

The fill-form action accepts the complete form payload as a command-line argument. Command-line arguments may be exposed through process inspection tools, shell history, command auditing, or process-monitoring systems.

The fill_form() function then includes the unredacted input in the form_data result property. The CLI serializes that result to standard output without filtering sensitive field names or values. Standard output is frequently retained by Agent runtimes, CI/CD systems, terminal capture tools, and centralized logging services.

Form data commonly contains passwords, access tokens, personal information, session values, or payment-related details. Consequently, this behavior creates multiple plaintext disclosure channels. The function also reports a successful submission even though no network request occurs, which may mislead callers about the operation's result.

Attack Path

  1. A user or Agent invokes the fill-form action and supplies sensitive fields in the JSON command-line argument.
  2. The operating system exposes that argument to any local process or monitoring facility authorized to inspect the process command line.
  3. The script parses the JSON and copies every supplied value into results["form_data"].
  4. The script serializes the complete result to standard output.
  5. Terminal history, Agent execution records, CI logs, or centralized logging systems may retain the exposed values ...[truncated 1027 chars]
Remediation
View remediation

Remediation Suggestions

  1. Do not accept confidential form values through command-line arguments. Read them from standard input, an appropriately permission-restricted file, or a dedicated secret-management interface.
  2. Remove the form_data property from the returned result. If diagnostic information is required, return only non-sensitive field names or a redacted summary.
  3. Implement explicit redaction for common sensitive fields such as password, token, secret, authorization, cookie, and payment-related values. Prefer allowlisting safe metadata over relying solely on field-name matching.
  4. Ensure logs and exception messages never include raw form payloads.
  5. Return a truthful operation state. Do not report "submitted" or "Form submitted successfully" unless an actual submission has completed successfully and its response has been validated.
  6. Add automated tests verifying that secrets supplied to the form workflow do not appear in returned objects, standard output, error output, or log records.
  7. Document secure input handling requirements and advise operators to restrict access to execution logs and apply suitable retention policies.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill advertises browser automation, web scraping, and automated form filling without warning that it can interact with external sites, submit data, trigger side effects, or collect potentially sensitive information. This omission can cause users or downstream agents to invoke the skill in unsafe contexts, increasing the chance of privacy violations, unauthorized actions, or unintended impact on third-party systems.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.