web-browser-review
Warn
Audited by Socket on Mar 31, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the core purpose is coherent for visual QA, but the footprint is broader than a simple review skill because it executes project scripts, edits code autonomously, and depends on a separate browser skill/toolchain outside the publisher's direct trust boundary. Main concerns are transitive trust in /browse, execution of local dev scripts, and prompt-injection risk from untrusted web content combined with Bash/write access; this is not confirmed malware.
Confidence: 84%Severity: 69%
Audit Metadata