baoyu-danger-gemini-web

Fail

Audited by Socket on Jun 28, 2026

2 alerts found:

MalwareAnomaly
MalwareHIGH
SKILL.md

[Skill Scanner] Backtick command substitution detected (AITech 9.1.4) [CI003]

Confidence: 70%Severity: 7500%
AnomalyLOW
scripts/gemini-webapi/utils/load-browser-cookies.ts

This module is designed to automate obtaining authenticated Google (Gemini) cookies by launching or attaching to Chrome via the DevTools Protocol, polling for session readiness, and persisting cookies to disk. The code does not contain obvious obfuscated malware, remote command/backdoor behavior, or calls to attacker-controlled endpoints. However, it performs sensitive actions: retrieving and storing authentication cookies and controlling a browser process. That behavior is high-risk from a credential-exposure perspective and could be misused to harvest credentials if used without explicit user consent. Recommend treating this component as sensitive: audit its use, ensure the user knows cookies will be extracted and stored, restrict access to the cookie cache file, and verify provenance of the package before use.

Confidence: 85%Severity: 65%
Audit Metadata
Analyzed At
Jun 28, 2026, 03:19 AM
Package URL
pkg:socket/skills-sh/muratcankoylan%2Fbaoyu-skills%2Fbaoyu-danger-gemini-web%2F@db9c2c6a32a0a3909321a317dd4aecbc044d4a4e33fe757a6656d324d6f0b687
Security Audit — socket — baoyu-danger-gemini-web