remote-browser

Warn

Audited by Socket on Sep 29, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
scripts/instances.sh

The script has deployment-management functionality, but unvalidated registry directory names can reach JavaScript evaluation in list, and a tampered configured URL can receive the stored bearer token in status. The delete directory prefix check also permits path traversal if the config is attacker-controlled. These risks depend on control of local registry/configuration data; no clear standalone malware behavior is present.

Confidence: 96%Severity: 68%
AnomalyLOW
template/src/index.ts

No clear malware behavior is present. The authenticated browser-fetch and session endpoints permit navigation to arbitrary HTTP/HTTPS URLs without host or address restrictions, creating a meaningful SSRF risk if the browser can reach internal or sensitive network resources. Restrict destinations and account for redirects and DNS resolution.

Confidence: 97%Severity: 69%
Audit Metadata
Analyzed At
Sep 29, 2026, 10:10 AM
Package URL
pkg:socket/skills-sh/itamaker%2Fskills%2Fremote-browser%2F@9c53a69250dfd7de4a558fb719f20d6f2fedc06b5c6476b6ff41e8e9a2bb1bfc
Security Audit — socket — remote-browser