autobrowse

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Anomaly
AnomalyLOW
codegen/runners/lib/tsx-runner.mjs

This is an automated verification runner that installs dependencies, launches a TypeScript script, captures its output, and records a screenshot directory. It contains powerful intentional process-execution behavior, but the visible code does not show credential theft, network exfiltration, persistence, destructive file operations, cryptomining, or obfuscated payloads. The main security concern is that untrusted `--out-dir` or `--script` values can cause arbitrary npm lifecycle scripts or TypeScript code to execute, with inherited environment access.

Confidence: 98%Severity: 62%
Audit Metadata
Analyzed At
Sep 15, 2026, 01:48 AM
Package URL
pkg:socket/skills-sh/browserbase%2Fskills%2Fautobrowse%2F@38dfdd5491069d434b966d0e4fdbf0caf24018e35ae94841417937d659f9f132
Security Audit — socket — autobrowse