jev-browser-choice

Warn

Audited by Socket on Sep 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core capability fits the stated purpose, and direct TypeSafe API usage would be proportionate, but the skill reads a local API key file and can route both page data and credentials through an unverifiable local router path. No confirmed malware or overt exfiltration beyond the declared API call, yet the undocumented intermediary and raw credential handling make the trust model weaker than a benign vendor-direct integration.

Confidence: 77%Severity: 58%
Audit Metadata
Analyzed At
Sep 21, 2026, 10:58 PM
Package URL
pkg:socket/skills-sh/0xnatoshi%2Fjev-codex-router%2Fjev-browser-choice%2F@258b0c6e26a24a7b3e6a9b654b22cc5e79c0802b73a9fcd8d0a7991b76ad606e
Security Audit — socket — jev-browser-choice