browser-automation-notte

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's browser-automation features broadly match its stated purpose, but the trust and data-flow model is inconsistent. It reads local Gooseworks credentials, then routes Notte operations and sensitive session artifacts through a Gooseworks proxy instead of Notte's official API, creating disproportionate credential and data exposure.

Confidence: 89%Severity: 78%
Audit Metadata
Analyzed At
Apr 28, 2026, 01:08 PM
Package URL
pkg:socket/skills-sh/gooseworks-ai%2Fgoose-skills%2Fbrowser-automation-notte%2F@0de7e97848522dbfacc588bd8fa4eca4d11b22a3