setup-browser-cookies
Warn
Audited by Socket on Jun 14, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The main cookie-import capability matches the stated QA/authentication purpose, and the only remote installer is an official Bun script with checksum verification. However, the skill is over-scoped: it mixes browser-cookie access with unrelated gstack routing, vendoring migration, file edits, and git commits, giving it a broader footprint than necessary for a cookie helper. No clear credential exfiltration endpoint is shown, so this is not confirmed malware, but it carries medium security risk due to sensitive cookie handling and disproportionate project-modifying behavior.
Confidence: 100%Severity: 60%
Audit Metadata