Back to plugin

Security audit

Browser Automation

Security checks for vulnerabilities and agentic risk

Overview

This browser automation plugin is mostly transparent, but it enables high-impact browser/session access and writes executable skill files into workspaces by default, so users should review it before installing.

Install only if you want agents to control a real browser session. Review the defaults before enabling it: consider setting syncWorkspaceSkill=false if you do not want workspace skill files written automatically, manageBrowserConfig=false if you want to manage CDP and SSRF settings yourself, and avoid OPENCLAW_CHROME_SEED_PROFILE=1 unless you accept copying cookies/logins/history into the automation profile. Keep evaluate and upload disabled unless specifically needed.

SkillSpector was not run because this plugin release contains no bundled skills.

Static analysis

No suspicious patterns detected.