reflex-browser

Warn

Audited by Socket on Apr 10, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The browser-automation purpose broadly matches the capabilities, but the install trust story is weak: a private tokenized registry plus undocumented agent/runtime download commands create a notable supply-chain risk. No clear credential exfiltration or overtly malicious behavior is shown, but the unverifiable install path and arbitrary web interaction make this skill medium-high risk.

Confidence: 79%Severity: 74%
Audit Metadata
Analyzed At
Apr 10, 2026, 12:14 PM
Package URL
pkg:socket/skills-sh/Fruffel%2Freflex-cli-skill%2Freflex-browser%2F@40dcc5a5f406272398b821966f9f705a6b353365