browser

Warn

Audited by Socket on Sep 12, 2026

1 alert found:

Security
SecurityMEDIUM
scripts/eval.cjs

This module is a high-risk execution bridge: it takes attacker-/user-supplied JavaScript from the command line and performs `Runtime.evaluate` via Chrome DevTools Protocol inside a live page context, then prints returned values and exception text. While it contains no explicit persistence, network exfiltration to remote domains, or obfuscated payloads in this snippet, its primary function provides arbitrary code execution capability in the browser session if the CLI argument is attacker-influenced and/or if the local CDP endpoint is exposed/accessible. Treat as potentially dangerous and restrict invocation and CDP exposure.

Confidence: 82%Severity: 92%
Audit Metadata
Analyzed At
Sep 12, 2026, 05:22 AM
Package URL
pkg:socket/skills-sh/oldwinter%2Fskills%2Fbrowser%2F@c714037ab90f3fa168e618f46b5a82b2e14688f1e05d61d6e4e10624e58f0364
Security Audit — socket — browser