browser-use

Warn

Audited by Socket on Mar 26, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core browser-automation purpose is coherent and the extension provenance appears legitimate, but the skill inserts an undocumented local relay/wrapper with a non-standard token variable while reusing the user's authenticated browser session. The capability set is high-impact and data/token flow is not fully verifiable from the supplied skill.

Confidence: 81%Severity: 66%
Audit Metadata
Analyzed At
Mar 26, 2026, 01:10 AM
Package URL
pkg:socket/skills-sh/cklxx%2Felephant.ai%2Fbrowser-use%2F@780ff235bd54997a6ea43bb4c5651abf3d6dbdbf