ego-browser

Warn

Audited by Socket on Sep 13, 2026

2 alerts found:

SecurityAnomaly
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the browser automation capabilities are largely aligned with the stated purpose, but the trust model is high risk. The skill requires installing and running an unverifiable closed-source same-org binary from a downloaded DMG, removes quarantine, and then uses the user's authenticated browser state to act on websites. This is coherent for a browser skill, but the install and credential/session exposure are disproportionate enough to classify as suspicious rather than benign.

Confidence: 88%Severity: 78%
AnomalyLOW
scripts/install.sh

No explicit backdoor/persistence/exfiltration logic is evident in this installer/launcher script itself. However, it creates a significant macOS supply-chain risk: it downloads and mounts a remote DMG (and possibly runs an included .pkg) without verifying integrity or authenticity, then removes com.apple.quarantine and performs privileged installation into /Applications before launching. If the CDN content (or transport path) were tampered with, this script would directly deliver and execute the attacker’s payload with elevated installation impact.

Confidence: 74%Severity: 62%
Audit Metadata
Analyzed At
Sep 13, 2026, 03:56 PM
Package URL
pkg:socket/skills-sh/celeroncoder%2Fskills%2Fego-browser%2F@024498fa86902dec76c36e3f958f63164a4c83f596a873f86f329e4cb9144662
Security Audit — socket — ego-browser