auto-perf-optimize

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The skill is largely coherent with its stated VS Code performance-investigation purpose, but it carries meaningful security risk because it operates a real authenticated editor on the user's machine, can trigger real tool/file actions, and includes an unpinned third-party `npx agent-browser` execution path. This looks more like a legitimate but medium-risk automation skill than a credential-harvesting or overtly malicious one.

Confidence: 87%Severity: 62%
Audit Metadata
Analyzed At
Apr 30, 2026, 08:50 AM
Package URL
pkg:socket/skills-sh/microsoft%2Fvscode%2Fauto-perf-optimize%2F@f16ba4ee7f22ac384a23dc92f4bc3d4c357ad588