Back to plugin

Security audit

Unbrowse

Security checks for vulnerabilities and agentic risk

Overview

This is a clearly disclosed hosted web-automation plugin, but it can use Unbrowse to access signed-in websites and canvas context, so users should install it only if they trust that service.

Install this only for work where you are comfortable routing web pages, tasks, canvas content, and signed-in website actions through Unbrowse. Keep the API key in a secret manager, review any write, purchase, post, or account-changing action before it runs, and prefer pinned/package-managed installation paths over ad hoc npx execution.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Rp1

Medium
Category
MCP Rug Pull
Confidence
87% confidence
Finding

The skill instructs users to run npx unbrowse mcp, which resolves and executes the latest published package at runtime rather than a pinned, reviewed version. This creates a supply-chain risk: if the package or one of its dependencies is compromised, or a breaking release is published, agents may execute untrusted code with the user's local privileges.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The tool unbrowse.canvas.read explicitly permits reading the user's live canvas, revisions, selected context, and conversation, but the manifest text does not present a strong user-facing privacy warning or consent boundary. Because this data can include sensitive planning context, prior outputs, or other private workspace information, silent or unexpected access creates privacy and data-exposure risk.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest allows broad natural-language task execution via tools like unbrowse.run, which can map vague prompts into powerful website actions without explicit trigger boundaries or per-action confirmation requirements. In a skill that can access signed-in sites, reuse sessions, and perform durable runs, this increases the chance of overbroad or unintended actions being initiated from ambiguous user input.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · skills/unbrowse/references/tools.json (reported line 255)May include surrounding context.

json
},
    {
      "name": "unbrowse.browse.act",
      "description": "click | fill | select | check | press | wait on a @ref, or autofill. For fill, pass `name` as the business field (origin, date, email…) so the learned API gets readable inputs. For logins never ask the user for a password: `autofill` fills the page's login form (username or email, password, 2FA code) from the user's Unbrowse password manager, or fill one @ref with `vault: \"username\" | \"email\" | \"password\" | \"totp\"`. The values go straight into the page and never pass through you. If no login is saved for the site, the error carries a link: give it to the user, wait with unbrowse.credentials.status, then repeat the action.",
      "inputSchema": {
        "type": "object",
        "properties": {

Static analysis

Detected: suspicious.env_credential_access

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
dist/index.js:17
Evidence
var env = (name) => (typeof process !== "undefined" ? process.env?.[name] : undefined) || undefined;