agent-browser

Warn

Audited by Socket on May 13, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the browser automation purpose broadly matches the capabilities, but the trust model is inconsistent. The main issues are the transitive `npx skills add` installation path, broad `Bash(belt *)` scope, and the combination of untrusted web browsing with action-taking features that could amplify prompt injection or unintended submissions. This looks more like a high-risk skill design than confirmed malware.

Confidence: 85%Severity: 74%
Audit Metadata
Analyzed At
May 13, 2026, 03:04 PM
Package URL
pkg:socket/skills-sh/inference-skills%2Fskills%2Fagent-browser%2F@bc1456f3a349356cd9c11457678001f6885839a8
Security Audit — socket — agent-browser