sellersprite-rpa

Warn

Audited by Socket on Aug 19, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/bridge_browserskill.py

This module is not obviously malicious by itself, but it is security-sensitive infrastructure: it executes an external bsk binary determined by environment/PATH (and an unusual hardcoded Windows fallback) and delegates high-impact actions to that binary. In particular, caller-provided code is forwarded to bsk’s evaluate capability and caller-provided URLs and screenshot output paths are forwarded without validation. Treat this as a potential execution-primitive and supply-chain risk surface; ensure the bsk binary is trusted/integrity-checked and that url/code/path inputs are controlled or strictly allowlisted by the calling application.

Confidence: 62%Severity: 62%
Audit Metadata
Analyzed At
Aug 19, 2026, 09:51 AM
Package URL
pkg:socket/skills-sh/liangdabiao%2Fsellersprite-rpa-skills%2Fsellersprite-rpa%2F@47fc0061352eb8056c3afe41be778b270c119421
Security Audit — socket — sellersprite-rpa