js-reverse-mcp-debugging

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core debugging capabilities align with the stated purpose, and the main npm install path is coherent. Risk comes from the optional anti-detection stack: the skill encourages use of a separate third-party browser binary that auto-downloads and executes, plus it exposes rich browser/session data and execution primitives against untrusted web content. This looks like a legitimate but high-risk reverse-engineering skill, not confirmed malware.

Confidence: 89%Severity: 74%
Audit Metadata
Analyzed At
Sep 15, 2026, 06:36 AM
Package URL
pkg:socket/skills-sh/reason-machines%2Fmcp-skills%2Fjs-reverse-mcp-debugging%2F@2bb76809951e2c83d64143e3ea6c3f5b8a814bc0d2e6ba44c0afd8bdf803881e
Security Audit — socket — js-reverse-mcp-debugging