agent-browser

Warn

Audited by Socket on Apr 13, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core browser automation capability matches the stated purpose, but the skill is high-risk because it combines arbitrary web interaction, credential/session handling, untrusted page ingestion, and Bash execution with few default safeguards. The most notable inconsistency is the silent third-party update check and transitive `npx skills update` flow, which extends trust beyond the claimed upstream source.

Confidence: 87%Severity: 79%
Audit Metadata
Analyzed At
Apr 13, 2026, 04:24 PM
Package URL
pkg:socket/skills-sh/abpai%2Fskills%2Fagent-browser%2F@396798b9f411bb753c2d2210d8a50a95231458a3
Security Audit — socket — agent-browser