native-devtools-mcp-automation

Warn

Audited by Socket on May 19, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill’s capabilities mostly match its stated purpose as a native/browser/device automation MCP server, but its footprint is very powerful: screen capture, accessibility access, browser/device control, CDP eval, and optional wildcard auto-approval. Install paths are mostly standard and same-project, though publisher identity is not clearly verifiable and `npx -y` is unpinned. No clear credential theft or exfiltration endpoint is shown, so this is not confirmed malware, but it is a high-risk automation skill whose permissions and action scope can cause significant real-world impact.

Confidence: 85%Severity: 74%
Audit Metadata
Analyzed At
May 19, 2026, 03:18 AM
Package URL
pkg:socket/skills-sh/Aradotso%2Fdevtools-skills%2Fnative-devtools-mcp-automation%2F@0c28da434e01ebd1142edbcdd3083adf67fd88c6