visual-diff

Warn

Audited by Socket on May 7, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core behavior matches a visual diff skill, but its footprint is broader than necessary because it installs/executes unpinned npm tooling, opens remote-debug Chrome, and chains multiple unreviewed sub-skills. Data flow is mostly local and proportionate, with no clear credential harvesting or exfiltration, so this is not malicious; the main concern is medium supply-chain and transitive trust risk.

Confidence: 87%Severity: 61%
Audit Metadata
Analyzed At
May 7, 2026, 03:11 AM
Package URL
pkg:socket/skills-sh/hixuanxuan%2Fbrowser-automation%2Fvisual-diff%2F@389d577c03e92cc90d0019f4cba491d6bb4bc003
Security Audit — socket — visual-diff