chrome-devtools

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/evaluate.js

This script intentionally executes user-provided JavaScript inside a browser page context (via page.evaluate + eval) and navigates to user-provided URLs without validation. The code itself does not contain obvious malware, obfuscation, or hardcoded secrets, but it provides a powerful primitive that can be abused to read sensitive page data or perform exfiltration when given untrusted input. Treat use of this tool as high-risk if scripts or URLs can be influenced by untrusted parties; otherwise it is expected functionality for a browser automation CLI.

Confidence: 90%Severity: 60%
Audit Metadata
Analyzed At
Apr 29, 2026, 09:20 AM
Package URL
pkg:socket/skills-sh/duc01226%2Feasyplatform%2Fchrome-devtools%2F@c21bec425948fd1d4d6cfbed696a81b13da76d8c