browse

Warn

Audited by Socket on Jun 20, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

Overall suspicious rather than malicious. The core Browserbase/browser automation behavior is aligned with the stated purpose and the npm install path appears official, but the skill is broad, can attach to existing browser state, forwards API credentials into an external CLI, and most importantly can install additional Browse.sh skills, creating a transitive trust chain that expands agent capabilities beyond the reviewed skill.

Confidence: 89%Severity: 63%
Audit Metadata
Analyzed At
Jun 20, 2026, 09:28 AM
Package URL
pkg:socket/skills-sh/browserbase%2Fstagehand%2Fbrowse%2F@ce2dbeb8c5fd1d6ccb771dcd7d2db6caa371e5fc17be057ce1e5b8aea8a54619
Security Audit — socket — browse