agent-browser
Warn
Audited by Socket on Apr 13, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The core browser automation capability matches the stated purpose, but the skill is high-risk because it combines arbitrary web interaction, credential/session handling, untrusted page ingestion, and Bash execution with few default safeguards. The most notable inconsistency is the silent third-party update check and transitive `npx skills update` flow, which extends trust beyond the claimed upstream source.
Confidence: 87%Severity: 79%
Audit Metadata