Public AI agent scan brief
browser-use/browser-use AI agent security scan
Partial no-execution triage for the public browser-use repo. This is a heuristic scan of 90 selected public text files, not a commissioned audit, vulnerability disclosure, or security certification. These are not confirmed vulnerabilities.
Top findings
Browser agents need explicit session and credential boundaries
The scan snapshot saw 99,596 stars and review signals around credential handling, remote browser or sandbox entry points, and write-action test visibility. A paid review would validate real source paths, runtime defaults, redaction behavior, browser session controls, and launch notes.
Evidence slice
Files that triggered review signals
Credential and workflow signals appeared in workflow and eval paths such as `.github/workflows/claude.yml`, `.github/workflows/cloud_evals.yml`, `.github/workflows/docker.yml`, `.github/workflows/eval-on-pr.yml`, and `.github/workflows/publish.yml`.
Browser and remote runtime signals appeared near `browser_use/skill_cli/README.md`, `examples/browser/playwright_integration.py`, `examples/browser/using_cdp.py`, `examples/integrations/agentmail/email_tools.py`, and `examples/sandbox/example.py`.
Paid handoff
Convert this scan into a fixed-scope review
- Confirm the current browser agent surface, deployment mode, and credentials in scope.
- Review page content, click, form, download, cookie, and JavaScript execution boundaries.
- Validate redaction, auth gates, allowlists, and regression tests against current source.
- Pay USD $1,000 only after written scope acceptance.