web-browser-review

Warn

Audited by Socket on Mar 31, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core purpose is coherent for visual QA, but the footprint is broader than a simple review skill because it executes project scripts, edits code autonomously, and depends on a separate browser skill/toolchain outside the publisher's direct trust boundary. Main concerns are transitive trust in /browse, execution of local dev scripts, and prompt-injection risk from untrusted web content combined with Bash/write access; this is not confirmed malware.

Confidence: 84%Severity: 69%
Audit Metadata
Analyzed At
Mar 31, 2026, 03:11 PM
Package URL
pkg:socket/skills-sh/parandurume-labs%2Fconductor%2Fweb-browser-review%2F@2d5b81c4eb8d887afbdf94a2ebd3fb7c9c6c7b0f