ghost-browser
Audited by Socket on Sep 14, 2026
3 alerts found:
SecurityAnomalyx2SUSPICIOUS: the skill's browser-automation purpose is plausible, and its package install path is mostly consistent with that purpose, but its footprint is high-risk for an AI skill because it controls a real logged-in browser session across arbitrary sites, can be overridden to perform irreversible actions, and may route sensitive browsing context or prompts through a third-party gateway (Euri). The biggest concern is not confirmed malware but disproportionate autonomy and unverifiable local script behavior against authenticated sessions.
The code is an LLM-driven browser automation wrapper rather than evident malware. It does not directly steal credentials, execute system commands, or contact a hardcoded suspicious destination. However, it presents a meaningful security risk because it controls a potentially authenticated browser session, sends page data to an external LLM service, accepts unrestricted task input, and relies on prompt-based safety controls that can be bypassed by model or webpage instructions. Use only with a trusted local CDP endpoint, trusted tasks, and careful data-handling controls. The fragment also appears syntactically incomplete if the displayed ending is exact.
The code is a local Chrome profile cloning and debugging launcher, likely intended to preserve browser logins for an automated agent. It does not show clear malicious intent or data exfiltration, but it handles sensitive browser state and exposes Chrome DevTools Protocol on localhost, which can permit local browser control and data access. It should be used only in a trusted local environment, with generated profile directories protected and removed afterward. The shown ending is syntactically incomplete if literal.