full-page-screenshot
Warn
Audited by Socket on May 15, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The advertised purpose is coherent, and the visible data flow stays local to Chrome DevTools with no clear credential harvesting or external exfiltration. However, this skill is mainly a catalogue pointer that asks the agent/user to install an upstream third-party skill from a personal GitHub repo via unpinned transitive install methods, which creates moderate supply-chain and trust-chain risk disproportionate to a simple discovery entry.
Confidence: 87%Severity: 58%
Audit Metadata