cloakbrowser

Warn

Audited by Socket on May 14, 2026

2 alerts found:

AnomalySecurity
AnomalyLOW
scripts/serve.sh

This file is primarily a process launcher and logger for an unobserved Python component (serve.py). It does not itself implement network exfiltration or credential theft, but it explicitly targets a “stealth Chromium” + CDP endpoint workflow and forwards arbitrary CLI arguments to serve.py without validation. The principal security concern is that serve.py may start a powerful remote automation surface whose behavior is controlled by user-supplied options; therefore, risk cannot be ruled out from this wrapper alone and serve.py should be reviewed before use.

Confidence: 63%Severity: 52%
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the install source is largely coherent and same-org, so this is not confirmed malware, but the skill’s purpose is to bypass bot detection and automate protected sites with a stealth browser. Its capabilities are high risk for AI-agent misuse, especially multi-step actions on arbitrary webpages and processing untrusted web content.

Confidence: 88%Severity: 79%
Audit Metadata
Analyzed At
May 14, 2026, 08:37 AM
Package URL
pkg:socket/skills-sh/OctavianTocan%2Fcloakbrowser-skill%2Fcloakbrowser%2F@32cbda5f88e8a0596c3860b7ba6e587c02f2d5f8
Security Audit — socket — cloakbrowser