Back to skill

Security audit

Nova Act Browser Automation

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed browser-automation helper, but its real-browser action authority is broader than its safety guarantees can reliably control.

Install only if you are comfortable giving the skill a Nova Act API key and allowing it to drive a real browser against URLs you provide. Use it for read-only browsing and extraction on public sites, avoid logged-in financial/account/admin pages, avoid internal or localhost URLs, and review/delete Nova Act trace files because they can contain screenshots and page content. Do not rely on the advertised 'never' safety guarantees for purchases, posts, submissions, bookings, or destructive actions without your own confirmation boundary.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/nova_act_runner.py:31
Finding

Material-Impact Safety Controls Are Bypassable and Prompt-Only

Content
View full analysis
list[str]: """Check if task involves material-impact actions. Returns triggered keywords.""" task_lower = task.lower() triggered = [kw for kw in MATERIAL_IMPACT_KEYWORDS if kw in task_lower] if triggered: print(f"Safety: Material-impact keywords detected ({', '.join(triggered)}). " f"Will stop before completing irreversible actions.", file=sys.stderr) return triggered def apply_safety_guardrails(task: str, triggered_keywords: list[str]) -> str: """Append safety instructions to task prompt when material-impact keywords detected.""" if triggered_keywords: return task + SAFETY_SUFFIX return task ``` ```python triggered = check_material_impact(task) safe_task = apply_safety_guardrails(task, triggered) cookbook = load_cookbook() # Load safety guidelines at runtime api_key = os.environ.get("NOVA_ACT_API_KEY") if not api_key: print("Error: NOVA_ACT_API_KEY environment variable ...[truncated 2723 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/nova_act_runner.py:68
Finding

URL Validation Allows Access to Private, Loopback, and Metadata Services

Content
View full analysis
str: parsed = urlparse(url) if parsed.scheme not in ALLOWED_SCHEMES: print(f"Error: URL scheme must be http or https, got: {parsed.scheme!r}", file=sys.stderr) sys.exit(1) if not parsed.netloc: print(f"Error: URL must include a hostname: {url}", file=sys.stderr) sys.exit(1) return url ``` ### Technical Analysis The validation routine only verifies that the URL uses HTTP or HTTPS and includes a network location. It does not reject: - Loopback addresses such as `127.0.0.1` or `::1`. - RFC1918 private addresses. - Link-local addresses. - Cloud instance metadata addresses such as `169.254.169.254`. - Reserved or otherwise non-public address ranges. - Hostnames that resolve to prohibited addresses. - Redirects from an initially public URL to an internal destination. Because the URL is passed to `NovaAct(starting_page=url)`, the browser runs from the local execution environment and may reach services that are inaccessible to an external requester. This creates a server-side-request-forgery-like browser primitive with additional interaction capabilities. ### Attack Path 1. An attacker supplies an internal URL, such as a loopback service, RFC1918 host, or link-local metadata endpoint. 2. `urlparse()` recognizes the HTTP or HTTPS scheme and a nonempty network location. 3. `validate_url()` returns the URL without checking the resolved IP address. 4. Nova Act launches the browser against the internal destination. 5. The task instructs the browser agent to inspect, extract from, or interact with the internal service. 6. Alternatively, an attacker supplies a public URL that redirects or resolves through DNS to a prohibited internal address if subsequent navigat ...[truncated 894 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/nova_act_runner.py:2
Finding

Unpinned Runtime Dependencies Create a Supply-Chain Risk

Content
View full analysis
=3.10" # dependencies = [ # "nova-act", # "pydantic>=2.0", # "fire", # ] # /// ``` ### Technical Analysis The PEP 723 dependency declaration does not pin `nova-act` or `fire` to exact reviewed versions. `pydantic` is constrained only by a minimum version and has no exact version or upper bound. When the script is launched with `uv run`, dependency resolution can select releases that differ from those present during the audit. This prevents reproducible execution and expands the supply-chain trust boundary to future package releases. A compromised upstream package, malicious maintainer release, or newly introduced dependency could execute code during installation or import. The risk is especially significant because these dependencies run inside the same Python process as the skill. They can access the process environment, including `NOVA_ACT_API_KEY`, local files available to the user, network connectivity, and browser automation capabilities. ### Attack Path 1. An upstream package or one of its transitive dependencies publishes a compromised release that still satisfies the broad dependency declaration. 2. A later invocation executes the script through `uv run`. 3. The resolver selects and downloads the newer release because no exact audited version and integrity lock prevent the change. 4. Malicious package code executes during installation, import, or normal library initialization. 5. The malicious code operates with the local user's process privileges and may read environment variables, access files, make network requests, or alter browser behavior. ### Impact Assessment A compromised dependency would execute with the privileges of the user running the skill. Its potential scope inclu ...[truncated 578 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
98% confidence
Finding

Passing env={**os.environ} forwards the entire parent process environment to the subprocess, not just NOVA_ACT_API_KEY. If the runner script, its dependencies, or browser automation path are compromised or verbose logs/traces are produced, unrelated secrets such as cloud credentials, tokens, and internal configuration can be exposed or misused.

Content

Scanner excerpt · SKILL.md (reported line 93)May include surrounding context.

md
result = subprocess.run(
    ["uv", "run", script, "--url", url, "--task", task],
    capture_output=True, text=True, env={**os.environ}
)
print(result.stdout)
if result.returncode != 0:

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill advertises and demonstrates capabilities to read environment variables, read local configuration files, and access the network, but it does not declare an explicit permission or tool scope. That creates a governance gap: an agent or user may invoke the skill without clear visibility into its access to secrets and external services, increasing the chance of overbroad execution and accidental data exposure.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: nova-act
description: Write and execute Python scripts using Amazon Nova Act for AI-powered browser automation tasks like flight searches, data extraction, and form filling.
homepage: https://nova.amazon.com/act
metadata:
  {