podman-browser

Warn

Audited by Socket on Aug 6, 2026

1 alert found:

Anomaly
AnomalyLOW
browse.js

No strong evidence of intentional malware (tracking/backdoor/credential theft/exfiltration) in this module. However, it is a security-sensitive headless browsing tool: it fetches attacker-controlled URLs (often leading to SSRF/internal exposure concerns in deployments), runs Chromium with sandbox disabled and shares host IPC (increasing impact if the browser is exploited), and performs runtime npm installation of Playwright without lockfile/checksum verification (supply-chain/integrity risk).

Confidence: 76%Severity: 56%
Audit Metadata
Analyzed At
Aug 6, 2026, 12:50 PM
Package URL
pkg:socket/skills-sh/ricardodantas%2Fskills%2Fpodman-browser%2F@90e51f5d617e2689f9dec55daf827d6073ba53cbfb74b9f44ba0aa5d102a6e0a
Security Audit — socket — podman-browser