surf
Fail
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: HIGHCREDENTIALS_UNSAFEREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [CREDENTIALS_UNSAFE]: A hardcoded bearer token (
sk-dev-proxy-123) is present in thereview.pyscript. Although it appears to be a placeholder for local development, it follows the pattern of an unsafe hardcoded credential. - [REMOTE_CODE_EXECUTION]: The
cdp_client.pyscript automatically installs missing Python dependencies (websocket-client,httpx) at runtime usingpip installwithout specifying versions, which is a risk for supply-chain attacks. - [COMMAND_EXECUTION]: The
scripts/lib/anti_avoidance_gate.pyscript executes arbitrary shell commands usingsubprocess.run(..., shell=True)based on commands defined in a JSON configuration file. This represents a significant execution capability that could be abused if the configuration is controlled by an attacker. - [EXTERNAL_DOWNLOADS]: The skill performs several external downloads, including
npm installfor its vendored CLI tool inscripts/ensure-surf-cli.shand agit cloneoperation inscripts/live_cdp_pointer_example.pyto fetch a bot-detection research repository. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest data from arbitrary web pages and process it through AI agents. This creates a wide attack surface for indirect prompt injection where hidden instructions on a webpage could attempt to hijack the agent's behavior or leverage the skill's powerful browser-control capabilities.
Recommendations
- AI detected serious security threats
Audit Metadata