Security audit
Browser Automation
Security checks for vulnerabilities and agentic risk
Overview
This browser automation plugin is mostly transparent, but it enables high-impact browser/session access and writes executable skill files into workspaces by default, so users should review it before installing.
Install only if you want agents to control a real browser session. Review the defaults before enabling it: consider setting syncWorkspaceSkill=false if you do not want workspace skill files written automatically, manageBrowserConfig=false if you want to manage CDP and SSRF settings yourself, and avoid OPENCLAW_CHROME_SEED_PROFILE=1 unless you accept copying cookies/logins/history into the automation profile. Keep evaluate and upload disabled unless specifically needed.
SkillSpector was not run because this plugin release contains no bundled skills.
Static analysis
No suspicious patterns detected.
