browser-testing-with-devtools

Warn

Audited by Socket on May 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s purpose and capabilities are largely coherent and it includes strong safety boundaries against browser-content prompt injection and credential access. The main issue is install trust: the documented `npx @anthropic/chrome-devtools-mcp@latest` does not match the official ChromeDevTools package name found in public docs, and it is unpinned runtime execution. That mismatch makes provenance uncertain and elevates risk, but there is no evidence of credential harvesting, exfiltration, or malicious intent in the skill itself.

Confidence: 92%Severity: 58%
Audit Metadata
Analyzed At
May 16, 2026, 11:52 AM
Package URL
pkg:socket/skills-sh/addyosmani%2Fagent-skills%2Fbrowser-testing-with-devtools%2F@0ae64a37757f7626284dd709641ca02dd9c8a964
Security Audit — socket — browser-testing-with-devtools