lightpanda-browser
Warn
Audited by Socket on Mar 20, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The browsing and automation capabilities broadly match the stated purpose, but the install trust is a major problem: the main install path uses an unverified personal GitHub raw script instead of an official same-org distribution path. Combined with arbitrary web-content processing, eval support, and credential/session handling, the skill presents high security risk even though it is not confirmed malware.
Confidence: 84%Severity: 81%
Audit Metadata