chrome-devtools

Warn

Audited by Socket on Jul 3, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/evaluate.js

This script intentionally executes user-provided JavaScript inside a browser page context (via page.evaluate + eval) and navigates to user-provided URLs without validation. The code itself does not contain obvious malware, obfuscation, or hardcoded secrets, but it provides a powerful primitive that can be abused to read sensitive page data or perform exfiltration when given untrusted input. Treat use of this tool as high-risk if scripts or URLs can be influenced by untrusted parties; otherwise it is expected functionality for a browser automation CLI.

Confidence: 90%Severity: 60%
Audit Metadata
Analyzed At
Jul 3, 2026, 01:37 AM
Package URL
pkg:socket/skills-sh/hotriluan%2Fai-command-center%2Fchrome-devtools%2F@6ba03c7c262e098f9d7053caef15a76a3b4f87242800c1d093ce71ab67d7ee24
Security Audit — socket — chrome-devtools