skyvern

Warn

Audited by Socket on Jun 13, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core purpose and capabilities are broadly aligned: official PyPI install, same-org API endpoint, and browser automation features match the skill description. Risk is elevated because the skill enables autonomous actions on arbitrary third-party sites, may handle credentials and sensitive page data through a hosted service, and official docs mention an optional third-party `mcp-remote` bridge that expands credential trust. Not malware, but high-impact and medium-risk for agent use.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 13, 2026, 07:52 AM
Package URL
pkg:socket/skills-sh/davepoon%2Fbuildwithclaude%2Fskyvern%2F@ec2539f1925cd6d790e5192be482f0e1b0e95db615e23717ce78f9bdc7495a25
Security Audit — socket — skyvern