browser-workflow-executor

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s testing purpose is mostly coherent, but its footprint expands into autonomous code changes, test rewriting, PR creation, and CI monitoring. The highest risks are indirect prompt injection from external web content and autonomous external actions through GitHub, not overt malware or credential theft.

Confidence: 90%Severity: 74%
Audit Metadata
Analyzed At
Mar 18, 2026, 10:25 PM
Package URL
pkg:socket/skills-sh/neonwatty%2Fclaude-skills%2Fbrowser-workflow-executor%2F@151fc0292eb55094b02e1578bc566e244c11536e