reflex-browser

Warn

Audited by Socket on Apr 7, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s capabilities fit its stated browser-automation purpose, and the Gitea registry setup is internally consistent, but the install path depends on a private token-authenticated package with limited public provenance. Main risk is supply-chain/install trust and the broad power of browser automation, not clear malicious behavior or credential harvesting.

Confidence: 82%Severity: 74%
Audit Metadata
Analyzed At
Apr 7, 2026, 08:42 PM
Package URL
pkg:socket/skills-sh/fruffel%2Freflex-browser-skill%2Freflex-browser%2F@372b2b5c95f5657d1bda2fb3326ba2e9ffcd6aac