browser-workflow-executor
Warn
Audited by Socket on Mar 18, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s testing purpose is mostly coherent, but its footprint expands into autonomous code changes, test rewriting, PR creation, and CI monitoring. The highest risks are indirect prompt injection from external web content and autonomous external actions through GitHub, not overt malware or credential theft.
Confidence: 90%Severity: 74%
Audit Metadata