agent-browser

Fail

Audited by Socket on Mar 8, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The skill presents a coherent concept for browser automation via a Playwright-backed CLI, with features that align to its stated purpose. However, the install/execution path (curl-script -> remote binary download -> checksum verification) constitutes a classic supply-chain risk due to unverifiable binary provenance and remote execution. The data flows could be legitimate (local outputs like video/snapshots) but risk data exfiltration via automated web interactions if not properly governed. Overall, the footprint is Suspicious: the capabilities align with the stated purpose, but the installation/download approach and potential for data leakage/credential exposure through the intermediary binary justify elevated scrutiny. Treat as suspicious until a verifiable, signed release channel and explicit data-flow/privacy controls are provided.

Confidence: 98%Severity: 65%
Audit Metadata
Analyzed At
Mar 8, 2026, 02:51 AM
Package URL
pkg:socket/skills-sh/1nfsh-s3%2Fskills%2Fagent-browser%2F@88f18f485076866448050ecea0d599ddef5ed15b
Security Audit — socket — agent-browser