browser-gui-inspect
Warn
Audited by Socket on Jul 30, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The core dependency path is official and consistent with the stated browser-inspection purpose, so this is not confirmed malware. However, the skill’s practical footprint exceeds its claimed read-only boundary: it can drive authenticated browser sessions, inspect full network traffic, and its own Watch Mode example performs a submitted create action despite the stated prohibition on config changes. Medium risk from broad authenticated browser access plus unpinned npx execution, but no clear evidence of credential harvesting or attacker-controlled exfiltration infrastructure.
Confidence: 87%Severity: 58%
Audit Metadata