browsing

Warn

Audited by Socket on Sep 25, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
chrome-ws

The fragment appears to be legitimate Chrome DevTools automation software, not malware. Its principal risks are inherent high-privilege features: arbitrary browser JavaScript/CDP execution, possible sensitive-data extraction, unrestricted output paths, execution of an environment-selected browser binary, and potential exposure of an unauthenticated debugging endpoint. These risks require trusted users and a loopback-only protected debugging port, but there is no evidence of covert malicious behavior in this file.

Confidence: 98%Severity: 62%
AnomalyLOW
lib/evaluation.js

This is a browser automation/evaluation utility. It intentionally provides arbitrary JavaScript execution in a selected page, creating a high-impact code-injection risk if its expression or WebSocket target can be controlled by untrusted input. Within a properly trusted automation boundary, the behavior is expected. No direct malicious behavior or malware indicators are present in the fragment.

Confidence: 98%Severity: 62%
Audit Metadata
Analyzed At
Sep 25, 2026, 05:35 AM
Package URL
pkg:socket/skills-sh/obra%2Fsuperpowers-chrome%2Fbrowsing%2F@e8bf669e8d3183660d6a7140f35e439d910bd9d8f51e1ea73b409aa2098ec5bf
Security Audit — socket — browsing