browser-use Security Audit Report
browser-use is an AI agent skill, created by browser-use and published at browser-use/browser-use. ClawSecure audited browser-use across 98 files through the 3-Layer Audit Protocol covering all ten OWASP ASI Top 10 categories, assigning a security score of 0/100 (High Risk). The 27 findings concentrate in Code Injection, ReDoS and Permissions Manifest, including Potentially dangerous code pattern detected: curl.*\|.*sh and Potentially dangerous code pattern detected: curl.*\|.*sh. 23 were rated high or critical severity.
Is browser-use safe?
ClawSecure audited browser-use and assigned a security score of 0/100 (High Risk), identifying 27 findings across Code Injection and ReDoS. Review the findings below before installing.
What did ClawSecure find in browser-use?
ClawSecure identified 27 findings in browser-use, concentrated in Code Injection, ReDoS and Permissions Manifest. 23 were rated high or critical severity. The most severe include Potentially dangerous code pattern detected: curl.*\|.*sh and Potentially dangerous code pattern detected: curl.*\|.*sh.
How was browser-use audited?
ClawSecure ran browser-use through its 3-Layer Audit Protocol with full OWASP ASI Top 10 coverage, scanning 98 files from browser-use/browser-use.
What does a score of 0 mean?
ClawSecure assigned browser-use a security score of 0/100, placing it in the High Risk range. This is driven by 27 findings led by Code Injection that should be addressed before use. ClawSecure derives this score with a weighted deduction model (critical -20, high -10, medium -5, low -2 from a base of 100).
Audit Findings for browser-use
ClawSecure detected 27 security findings in browser-use, spanning Code Injection, ReDoS and Permissions Manifest.
- high · Potentially dangerous code pattern detected: curl.*\|.*sh. Code Injection finding detected in
CLOUD.md. - high · Potentially dangerous code pattern detected: curl.*\|.*sh. Code Injection finding detected in
setup.sh. - high · Potentially dangerous code pattern detected: base64.*decode. Code Injection finding detected in
cloud_events.py. - high · Potentially dangerous code pattern detected: system\(. Code Injection finding detected in
gif.py. - high · Potentially dangerous code pattern detected: base64.*decode. Code Injection finding detected in
gif.py. - high · Potentially dangerous code pattern detected: base64.*decode. Code Injection finding detected in
judge.py. - high · Potentially dangerous code pattern detected: base64.*decode. Code Injection finding detected in
prompts.py. - high · Potentially dangerous code pattern detected: system\(. Code Injection finding detected in
service.py. - high · Potentially dangerous code pattern detected: base64.*decode. Code Injection finding detected in
service.py. - high · Potentially dangerous code pattern detected: curl.*\|.*sh. Code Injection finding detected in
service.py. - high · Potentially dangerous code pattern detected: exec\(. Code Injection finding detected in
service.py. - high · Potentially dangerous code pattern detected: system\(. Code Injection finding detected in
service.py.
Showing the 12 highest-severity of 27 findings. The full interactive list appears below.
3-Layer Audit Protocol
Security Recommendations for browser-use
Eliminate dynamic code execution
Fix ReDoS-prone patterns
Add a config.json permissions manifest
Related Security Research
Why Generic Scanners Fail at AI Agent Security→Beyond Static Scans: Why ClawSecure Verifies Agentic Intent→Related AI Agent Security Audits
Scanned on August 14, 2026. browser-use is one of thousands of agents audited by ClawSecure from the community-curated awesome-openclaw-skills list and the openclaw/skills repository.