Back to skill

Security audit

Browser Use 1.0.2

Security checks for vulnerabilities and agentic risk

Overview

This is a legitimate browser automation skill, but it needs review because it can use real browser login sessions, move cookies into cloud profiles, and expose local services through tunnels.

Install only if you intend to use browser-use for browser automation and are comfortable supervising sensitive modes. Prefer isolated Chromium for routine browsing. Before using real Chrome profiles, cloud profiles, cookie sync, public session sharing, or tunnels, confirm the exact account, domain, profile, and local port involved; avoid full-profile cookie sync and avoid plaintext cookie files such as /tmp/cookies.json.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:404
Finding

Plaintext Authentication Cookies Exported to a Predictable Temporary File

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:404-406
Vulnerability Type: Unsafe temporary-file handling of sensitive authentication data
Risk Level: Medium

bash
# Export cookies to file, manually edit, then import
browser-use --browser real --profile "Default" cookies export /tmp/cookies.json
browser-use --browser remote --profile <id> cookies import /tmp/cookies.json

Technical Analysis

The documented workflow exports browser cookies to the fixed path /tmp/cookies.json. Browser cookies can contain reusable session tokens that provide authenticated access without requiring a password or multi-factor authentication challenge.

The instructions do not require exclusive file creation, restrictive permissions, symlink protection, ownership validation, or deletion after import. Because /tmp is commonly shared and the filename is predictable, another local process or user may monitor, pre-create, replace, or read the file depending on operating-system protections and the CLI's file-creation behavior.

Exploitability therefore depends on the local threat model, filesystem permissions, and whether browser-use safely handles existing files and symbolic links. The documented pattern nevertheless fails to provide appropriate safeguards for highly sensitive authentication material.

Attack Path

  1. A user follows the advanced cookie synchronization workflow for an authenticated browser profile.
  2. The CLI exports cookies, potentially including active session tokens, to /tmp/cookies.json.
  3. A malicious local process or user monitors the predictable path, accesses a weakly protected file, or prepares the path as a symbolic link before export.
  4. The attacker copies the exported cookies or causes an unintended file write if symlink handling is unsafe.
  5. The attacker imports or injects captured session cookies into a browser and attempts to impersonate the user on affected domains.
  6. If the temp ...[truncated 805 chars]
Remediation
View remediation

Remediation Suggestions

  1. Avoid intermediate plaintext files by supporting direct, domain-scoped cookie transfer between profiles.
  2. If a file is unavoidable, create a unique private directory using a secure temporary-file API rather than a fixed /tmp/cookies.json path.
  3. Set the temporary directory to mode 0700 and the cookie file to mode 0600.
  4. Use exclusive creation and reject symbolic links and non-regular files.
  5. Validate file ownership and permissions before importing cookie data.
  6. Export only cookies for explicitly approved domains; do not default to a full-profile export.
  7. Delete the temporary file in a guaranteed cleanup operation immediately after import, including failure and interruption paths.
  8. Warn users that exported cookies are authentication credentials and should never be logged, committed, shared, or retained.
  9. Where available, use encrypted operating-system credential storage or an authenticated encrypted transfer mechanism.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

YARA rule 'info_stealer': Information stealer patterns (credential harvesting, browser data theft) [malware]

High
Category
YARA Match
Confidence
92% confidence
Finding

The cookie-sync guidance enables transferring authenticated browser state from a local Chrome profile into another environment, including a cloud profile, which can duplicate live session tokens. Even though the text includes some caution, this capability is inherently dangerous because it can expose account access, bypass re-authentication, and facilitate session theft or misuse if invoked too broadly or stored insecurely.

Content

Scanner excerpt · SKILL.md (reported line 369)May include surrounding context.

tep 2: Browse with the chosen profile

bash
# Real browser — uses local Chrome with existing login sessions
browser-use --browser real --profile "Default" open https://github.com

# Cloud browser — uses cloud profile with synced cookies
browser-use --browser remote --profile abc-123 open https://github.com

The user is already authenticated — no login needed.

Note: Cloud profile cookies can expire over time. If authentication fails, re-sync cookies from the local Chrome profile.

Step 3: Syncing cookies (only if needed)

If the user wants to use a cloud browser but no cloud profile has the right cookies, sync them from a local Chrome profile.

Before syncing, the agent MUST:

  1. Ask which local Chrome profile to use
  2. Ask which domain(s) to sync — do NOT default to syncing the full profile
  3. Confirm before proceeding

Check what cookies a local profile has:

bash
browser-use -b real profile cookies "Default"
# → youtube.com: 23
# → google.com: 18

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest description is very broad and can trigger this skill for generic browsing requests without clearly signaling high-risk capabilities like authenticated profile use, cookie handling, cloud sessions, or tunnels. That increases the chance an agent invokes the skill in contexts where users did not intend sensitive browser state, local services, or login sessions to be exposed.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This skill exposes capabilities for cloud browsing, tunneling local services, authenticated profile use, cookie export/import, and profile sync, but the top-level description lacks an immediate privacy/security warning. Without that warning, an agent may treat the skill as routine browsing automation and use sensitive features in ways that leak credentials, session tokens, internal apps, or local development environments.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.