agent-browser
Warn
Audited by Socket on May 13, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the browser automation purpose broadly matches the capabilities, but the trust model is inconsistent. The main issues are the transitive `npx skills add` installation path, broad `Bash(belt *)` scope, and the combination of untrusted web browsing with action-taking features that could amplify prompt injection or unintended submissions. This looks more like a high-risk skill design than confirmed malware.
Confidence: 85%Severity: 74%
Audit Metadata