cloudflare-browser

Warn

Audited by Socket on Sep 14, 2026

3 alerts found:

AnomalySecurityx2
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's browser automation capabilities fit its stated purpose, but its credential and traffic flow are routed through a custom workers.dev intermediary rather than Cloudflare's documented first-party CDP endpoint. This is not confirmed malware, but it creates meaningful credential-forwarding and data-flow risk.

Confidence: 87%Severity: 66%
SecurityMEDIUM
scripts/cdp-client.js

The code is a browser automation/CDP client, not clear malware. Its main risks are deliberate arbitrary JavaScript execution, arbitrary navigation, transmission of the CDP secret in a URL query string, and unsafe interpolation in click/type expressions. It should only be used with trusted callers and a trusted worker endpoint; click and type inputs should be safely serialized rather than interpolated. The supplied fragment also appears incomplete at the end, which may cause a syntax error.

Confidence: 97%Severity: 70%
SecurityMEDIUM
scripts/video.js

The code appears to implement a legitimate browser screenshot-to-video workflow and contains no clear malware or intentional backdoor. It has a significant command-injection vulnerability because the user-controlled output path is embedded in an execSync shell command. It also transmits the CDP secret in a query string and permits unrestricted URL navigation through the remote browser. Use spawnSync with an argument array, validate the output path, validate WORKER_URL, and apply URL/network restrictions appropriate to the worker environment.

Confidence: 98%Severity: 78%
Audit Metadata
Analyzed At
Sep 14, 2026, 04:05 PM
Package URL
pkg:socket/skills-sh/cloudflare%2Fmoltworker%2Fcloudflare-browser%2F@cbddf7efac413b3a856b75be01921dc3edd44e7f231bc506ff0ae4b14689e0e2
Security Audit — socket — cloudflare-browser