cloudflare-browser
Audited by Socket on Sep 14, 2026
3 alerts found:
AnomalySecurityx2SUSPICIOUS. The skill's browser automation capabilities fit its stated purpose, but its credential and traffic flow are routed through a custom workers.dev intermediary rather than Cloudflare's documented first-party CDP endpoint. This is not confirmed malware, but it creates meaningful credential-forwarding and data-flow risk.
The code is a browser automation/CDP client, not clear malware. Its main risks are deliberate arbitrary JavaScript execution, arbitrary navigation, transmission of the CDP secret in a URL query string, and unsafe interpolation in click/type expressions. It should only be used with trusted callers and a trusted worker endpoint; click and type inputs should be safely serialized rather than interpolated. The supplied fragment also appears incomplete at the end, which may cause a syntax error.
The code appears to implement a legitimate browser screenshot-to-video workflow and contains no clear malware or intentional backdoor. It has a significant command-injection vulnerability because the user-controlled output path is embedded in an execSync shell command. It also transmits the CDP secret in a query string and permits unrestricted URL navigation through the remote browser. Use spawnSync with an argument array, validate the output path, validate WORKER_URL, and apply URL/network restrictions appropriate to the worker environment.