browser-use

Warn

Audited by Socket on May 18, 2026

1 alert found:

Security
SecurityMEDIUM
references/setup.md

No direct malicious logic is visible in the provided excerpt because it is installation documentation rather than the installer/package code. However, the guide instructs users to run a remotely fetched script via `curl -fsSL ... | bash` without showing integrity verification, which is a significant supply-chain risk because it enables arbitrary code execution during installation. The malware probability is low based on the excerpt alone, but the overall security risk is moderate-to-high due to the high-impact installer execution pattern and reliance on downstream dependency downloads.

Confidence: 62%Severity: 70%
Audit Metadata
Analyzed At
May 18, 2026, 01:04 AM
Package URL
pkg:socket/skills-sh/bighardperson%2Fcomputer-science-skills-collection%2Fbrowser-use%2F@f70ef4cd1cb954d0575825f5d3350832fc291e8f
Security Audit — socket — browser-use