tabbit-browser-devtools-skill

Warn

Audited by Socket on Sep 14, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's purpose and capabilities mostly align: it reads Tabbit's local DevToolsActivePort and connects only to localhost CDP. The main concern is trust expansion: it asks the agent to install and rely on a separate third-party skill/tool (agent-browser), plus mutable GitHub/registry install paths. Data flow is local and proportionate, with no obvious credential harvesting or exfiltration, so this is not malicious, but the transitive trust and supply-chain footprint make it moderately risky.

Confidence: 89%Severity: 52%
Audit Metadata
Analyzed At
Sep 14, 2026, 07:43 AM
Package URL
pkg:socket/skills-sh/reason-machines%2Fdevtools-skills%2Ftabbit-browser-devtools-skill%2F@b07d3d25d4f4e04e7f7ee20216629b60f25e373ce6fae5f1718a49844dabe6e0
Security Audit — socket — tabbit-browser-devtools-skill