browser-cdp

Warn

Audited by Socket on Sep 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is internally coherent for browser/CDP automation, but its actual footprint is powerful and sensitive. The main concern is explicit extraction of browser auth tokens/cookies and arbitrary action execution in an authenticated browser session via a third-party CLI; data does not appear routed to attacker infrastructure, so this is high-impact capability rather than confirmed malware.

Confidence: 84%Severity: 62%
Audit Metadata
Analyzed At
Sep 1, 2026, 09:14 AM
Package URL
pkg:socket/skills-sh/qin1473692580-ux%2Foh-story-claudecode%2Fbrowser-cdp%2F@c79a2da15c549e1017db494f6c584fb4aed08ec2ed2ef4acefa298f59aba4861
Security Audit — socket — browser-cdp