Browser Automation
Warn
Audited by Socket on Jun 3, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill’s stated purpose matches its browser-automation capabilities, and there is no clear evidence of credential theft or covert exfiltration. However, it relies on an external MCP server, enables arbitrary site interaction, and exposes the agent to indirect prompt injection from untrusted web content, making it medium risk rather than benign.
Confidence: 84%Severity: 58%
Audit Metadata