agent-browser-core
Warn
Audited by Socket on May 15, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill’s stated purpose matches browser automation, and its upstream CLI appears to come from an official Vercel Labs source, which lowers supply-chain concern. However, the combination of Bash-level execution, arbitrary web automation, authenticated session handling, and exposure to untrusted web content makes the footprint broader and riskier than a narrowly scoped browser skill.
Confidence: 84%Severity: 58%
Audit Metadata