Back to skill

Security audit

Agent Browser

Security checks for vulnerabilities and agentic risk

Overview

The skill is a legitimate browser automation guide, but it under-discloses risks around saved login state, cookies, storage, and global package installation.

Review this before installing if you will use it with logged-in sites. Treat saved state files, cookies, and localStorage output like passwords: do not commit, share, or log them, and prefer low-privilege test accounts. Install the CLI in an isolated environment and pin or verify the package version where possible.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:195
Finding

Unpinned Global npm Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 195–199
Vulnerability Type: Unpinned third-party package installation from a mutable registry
Risk Level: Medium

Complete Code Snippet:

bash
npm install -g agent-browser
agent-browser install                     # Download Chromium
agent-browser install --with-deps         # Linux: + system deps

Technical Analysis

The installation instructions globally install the latest available agent-browser npm package without pinning a reviewed version or verifying package integrity or provenance. Because registry package contents can change after this skill has been audited, the effective code installed by users is not fixed to the reviewed documentation.

npm packages can execute lifecycle scripts during installation. A compromised package release or publishing account could therefore cause arbitrary code execution when a user follows the documented command. Global installation expands the affected environment beyond an isolated project. The subsequent agent-browser install command downloads Chromium, while --with-deps may install system dependencies and request elevated privileges, further increasing the supply-chain exposure and potential system impact.

Attack Path

  1. An attacker compromises the npm package, its publisher account, or another relevant supply-chain component.
  2. The attacker publishes a malicious release under the expected package name.
  3. A user follows SKILL.md and runs npm install -g agent-browser without an explicit version or integrity constraint.
  4. npm resolves the mutable latest release and installs it globally.
  5. Malicious lifecycle scripts or subsequently invoked package code execute with the installing user's privileges.
  6. If the user then runs agent-browser install --with-deps with elevated privileges, malicious package behavior may affect system-level files or dependency installation.

Impact As

...[truncated 539 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin agent-browser to an explicitly reviewed version rather than installing the mutable latest release.
  • Verify npm package provenance, publisher identity, registry source, and integrity before installation.
  • Prefer a project-local installation governed by a committed lockfile instead of a global installation.
  • Use npm integrity and provenance controls and an approved internal registry or package allowlist where available.
  • Disable lifecycle scripts during installation when they are unnecessary, then explicitly perform only reviewed setup actions.
  • Run Chromium and operating-system dependency installation with least privilege and avoid granting administrative access to unverified package code.
  • Document the exact trusted package version, expected integrity digest, registry URL, and required installation privileges.
  • Periodically review pinned versions and update them only after security assessment.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly documents saving and loading browser state files that can contain cookies and local/session storage, but it provides no warning that these artifacts may embed active session tokens or other secrets. In an agent context, this can lead to accidental credential persistence, unsafe sharing of auth.json files, or reuse of privileged sessions across tasks and users.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documentation exposes direct cookie and browser storage read/write capabilities without any guidance on handling sensitive values, privacy boundaries, or authorization constraints. In a browser-automation skill for AI agents, this increases the chance of agents extracting, modifying, or leaking session identifiers, CSRF tokens, or personal data during routine use.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.