Agent Economy Report

Skill code audit

CAUTION version 1.0.0 · audited 2026-09-09

browserbase @jamesfincher

This skill is a command-line wrapper around the Browserbase cloud-browser service. It lets an agent create, list, inspect and terminate remote browser sessions, keep logins alive between sessions using Browserbase "contexts", navigate to URLs, run arbitrary JavaScript on a page, read cookies, take screenshots and download session recordings and logs. All network traffic goes to Browserbase's own endpoints (api.browserbase.com / connect.browserbase.com); no other destination appears in the code, and there is no obfuscation, no download-and-execute, no persistence hooks and no payment or wallet handling. It reads the Browserbase API key and project ID from environment variables and writes only a small local file mapping friendly context names to IDs (~/.browserbase/contexts.json), plus files the user explicitly names for screenshots and recordings. The genuinely powerful parts are inherent to its purpose: arbitrary JavaScript execution in a possibly logged-in browser, dumping cookies of authenticated sessions to stdout, automatic CAPTCHA solving on by default, and recording every session by default. Anyone installing it should be aware that page content the browser visits is fed back into the agent, which is a prompt-injection surface, and that cookie dumps can reveal session tokens.

Instructions try to steer the agent beyond the declared purpose. The skill feeds untrusted web page content back to the agent: navigate --extract-text returns up to 50,000 characters of arbitrary page text (scripts/browserbase_manager.py:561-573) and execute-js returns arbitrary evaluated results (line 630). Text scraped from a hostile site could contain instructions that an agent then acts on, and the agent already holds the Browserbase API key and can run further execute-js in logged-in sessions. No injected instructions were found inside the package files themselves.

Declared purposeCreate and manage persistent Browserbase cloud browser sessions with authentication persistence, CAPTCHA solving, session recording, screenshots, browser automation (navigate/execute-js/extract text/cookies) and session cleanup.
Observed behaviorA single Python CLI (scripts/browserbase_manager.py) that uses the official browserbase SDK plus Playwright over CDP. It reads BROWSERBASE_API_KEY and BROWSERBASE_PROJECT_ID from the environment, talks only to api.browserbase.com (and a wss://connect.browserbase.com fallback URL containing the API key as a query parameter), stores a name->context-id map under ~/.browserbase/contexts.json, and writes screenshots/recordings to user-specified paths. Commands include execute-js (runs arbitrary user-supplied JavaScript in the session), get-cookies (returns all cookies as JSON on stdout), navigate with text extraction (up to 50k chars of page text returned), get-recording, get-logs and live-url. Sessions default to solve_captchas=True and record_session/log_session=True. No hidden endpoints, no encoded payloads, no shell execution, no persistence or scheduling, no credential transmission beyond the Browserbase auth header.
Verdict, rules onlySAFE
Verdict, AICAUTION
Final verdictCAUTION (never better than either pass)

Capabilities

capabilityvs purposedetail
networkneededHTTPS calls to api.browserbase.com via the browserbase SDK and urllib (delete-context at scripts/browserbase_manager.py:263), plus a CDP WebSocket to connect.browserbase.com. urllib.request.urlretrieve at line 698 fetches a recording URL returned by the API.
credentialsneededReads BROWSERBASE_API_KEY and BROWSERBASE_PROJECT_ID from the environment (lines 106, 112, 262, 522). The key is sent only to Browserbase, but is embedded in a WebSocket query string in the fallback connect URL (lines 187, 523).
browserneededDrives a remote Chromium via Playwright connect_over_cdp; can navigate, screenshot, extract page text, read all cookies and execute arbitrary JavaScript in an authenticated session.
filesystem_writeneededCreates ~/.browserbase (or $BROWSERBASE_CONFIG_DIR) and writes contexts.json (lines 46, 62); writes screenshots and recordings to paths the caller supplies (lines 577, 601, 694, 702).
filesystem_readneededReads the local contexts.json name->ID map (line 54). No other local files are read.
install_packagesneededDocumentation instructs the user to run pip/uv install of browserbase and playwright plus 'playwright install chromium' (README.md:42-43, SKILL.md:32-33); the script itself does not install anything.

Findings

severityfinding
mediumArbitrary JavaScript execution in a possibly authenticated browser
The execute-js command runs any JavaScript the caller supplies inside the remote browser session, which may be logged into real accounts via a persisted context. This is required for the declared automation purpose, but combined with agent-driven input it allows reading or acting on any page the session can reach.
scripts/browserbase_manager.py:630 result_value = page.evaluate(args.code)
mediumFull cookie dump printed to stdout
get-cookies returns every cookie of the browser context, including session tokens for authenticated sites, as JSON on stdout. Nothing is redacted, so the values enter the agent's transcript and any logs the host keeps. Needed for the stated feature set, but it is a real credential-exposure path.
scripts/browserbase_manager.py:664 "cookies": cookies,
lowAPI key embedded in a WebSocket URL
When the SDK does not return a connect URL, the script builds one with the API key as a query parameter (also at line 187). The destination is the legitimate Browserbase host, but keys in URLs are more likely to appear in error messages, proxy logs or exception output than keys in headers.
scripts/browserbase_manager.py:523 connect_url = f"wss://connect.browserbase.com?apiKey={api_key}&sessionId={session_id}"
mediumUntrusted web page text returned to the agent
navigate --extract-text injects up to 50k characters of scraped page content into the agent's context. Content from a hostile page can attempt to steer the agent, which holds the Browserbase credentials and can issue further execute-js commands. Callers should treat extracted text as data, not instructions.
scripts/browserbase_manager.py:561 text = page.evaluate("""
lowSession recording and logging enabled by default
Every session is video-recorded and logged on Browserbase's servers unless --no-record is passed (line 346-348). If the agent logs into sensitive accounts, credentials typed on screen and page contents are stored with the third-party provider. The skill card acknowledges this; users must opt out explicitly.
scripts/browserbase_manager.py:347 browser_settings["record_session"] = True
lowAutomatic CAPTCHA solving on by default
CAPTCHA solving is enabled for every created session (also line 331). This is a documented feature of Browserbase, but bypassing anti-bot challenges may violate the terms of service of target sites and is a policy risk rather than a code defect.
scripts/browserbase_manager.py:170 browser_settings={"solve_captchas": True},
lowDownloads a URL supplied by the API response to a local path
The recording download follows whatever URL the Browserbase API returns and writes it to the user-specified output path. The destination is not validated, so a compromised or unexpected API response could point at another host; the file is only saved, never executed.
scripts/browserbase_manager.py:698 urllib.request.urlretrieve(recording.url, args.output)
infoCreates a local config directory
The script creates ~/.browserbase (or the path in BROWSERBASE_CONFIG_DIR) and stores a JSON map of friendly names to context IDs. No credentials are written there and this is not a persistence or auto-start mechanism.
scripts/browserbase_manager.py:46 os.makedirs(base, exist_ok=True)
lowUnpinned dependencies
Dependencies use minimum-version ranges rather than pinned versions, so a future upstream release (or a compromised one) would be pulled in automatically at install time. The skill card notes this; installing in an isolated environment with pinned versions is safer.
scripts/requirements.txt:1 browserbase>=1.0.0
infoVersion mismatch between registry metadata and package
_meta.json declares version 1.0.0 while SKILL.md frontmatter declares 2.0.0. Cosmetic, but it makes it harder to know exactly which build is installed.
skill-card.md:45 1.0.0 (source: server release metadata; artifact frontmatter reports 2.0.0) <br>

0 AI finding(s) were dropped because their file, line or quote did not match the package.

Network destinations in the code

domainservice ratingwhere
api.browserbase.comnot in the service indexreferences/api-quick-ref.md:5
clawhub.ainot in the service indexskill-card.md:7
docs.example.comnot in the service indexSKILL.md:227
example.comnot in the service indexSKILL.md:149
myapp.comnot in the service indexSKILL.md:206
www.browserbase.comnot in the service indexSKILL.md:25

Other facts

Binaries invokedbash, pip, python, python3, uv
Environment variables readBROWSERBASE_CONFIG_DIR
Hard-coded walletsnone
Pipes a download to a shell0
eval / exec / subprocess0
base64 blobs0
File writes6
Persistence0

Files audited

filelinessha256
README.md10776e906811a799ba7…
SKILL.md266baf4332175568494…
_meta.json6d1286293e7a562b9…
references/api-quick-ref.md807e608d3f0f971fe9…
scripts/browserbase_manager.py911bda2517977121d0f…
scripts/requirements.txt21c4b1667dbc3d0f7…
skill-card.md48a879f72046a8bcf2…

For agents

JSON: https://agenteconomy.report/k/browserbase.audit.json · badge: https://agenteconomy.report/k/browserbase.audited.svg · skill rating: /k/browserbase · commission an audit of any skill: US$ 29 per version.

How this is computed

The complete published package of this exact version was downloaded from the registry and read statically; nothing was executed. A deterministic pass extracts network destinations, binaries, environment variables, writes, install commands, obfuscation markers, subprocesses and wallets, each with file and line. An AI then reads the whole package with those facts and writes the summary, the capabilities and the findings under a strict schema; every finding it produces must cite a file, a line and the exact text, or it is dropped. The final verdict is the worst of the two passes. The audit does not change the skill's trust tier (policy); the author may respond through the dispute channel and the response is published here. Commissioned by: the Agent Economy Report (free program: the 150 most downloaded skills, September 2026).