chrome-cdp
Warn
Audited by Socket on Sep 15, 2026
1 alert found:
AnomalyAnomalyscripts/cdp.mjs
LOWAnomalyLOW
scripts/cdp.mjs
The fragment appears to be a legitimate, documented Chrome DevTools Protocol CLI and daemon. It contains no evident malicious payload, credential harvesting, exfiltration endpoint, persistence mechanism, or destructive behavior. Its security impact is inherently high when invoked by an untrusted user because eval, evalraw, browser navigation, page inspection, and local IPC can control and read the user's browser session. The open command also permits broader browser URL schemes than nav. Use only in a trusted local environment and protect the runtime directory and executable access.
Confidence: 98%Severity: 62%
Audit Metadata