chrome-cdp

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/cdp.mjs

The fragment appears to be a legitimate, documented Chrome DevTools Protocol CLI and daemon. It contains no evident malicious payload, credential harvesting, exfiltration endpoint, persistence mechanism, or destructive behavior. Its security impact is inherently high when invoked by an untrusted user because eval, evalraw, browser navigation, page inspection, and local IPC can control and read the user's browser session. The open command also permits broader browser URL schemes than nav. Use only in a trusted local environment and protect the runtime directory and executable access.

Confidence: 98%Severity: 62%
Audit Metadata
Analyzed At
Sep 15, 2026, 10:37 AM
Package URL
pkg:socket/skills-sh/hanyu0001%2Fchrome-cdp-skill%2Fchrome-cdp%2F@1ae63cad11992f0351b321e0a05b9e37c7566425a45a65f7799308fbf035873a
Security Audit — socket — chrome-cdp