baoyu-danger-gemini-web

Warn

Audited by Socket on Jun 26, 2026

2 alerts found:

AnomalySecurity
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's core behavior mostly matches its stated purpose, but it uses an unofficial reverse-engineered Gemini web flow, handles sensitive browser cookies, may reuse local Chrome debugging sessions, and allows proxy-rerouted traffic. Install trust is moderate rather than high because Bun/npx are official tools, but the auth and data-flow model is riskier than an official API integration.

Confidence: 84%Severity: 58%
SecurityMEDIUM
scripts/gemini-webapi/utils/load-browser-cookies.ts
Audit Metadata
Analyzed At
Jun 26, 2026, 08:19 AM
Package URL
pkg:socket/skills-sh/guanyang%2Fopen-agent-hub%2Fbaoyu-danger-gemini-web%2F@451b0af4adc0e9b9af87b729e971da49b081ae4c635291ff54d4e4981c1dfb7b
Security Audit — socket — baoyu-danger-gemini-web