browser-qa

Warn

Audited by Socket on Apr 23, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core browser-QA capabilities align with the stated purpose, and there is no clear malware behavior or installer abuse in the skill itself. The main issue is data-flow integrity: screenshots are explicitly uploaded to an unrelated third-party service, which is unnecessary for local QA and can expose sensitive UI data. The combination of arbitrary web-content handling plus browser control and shell access also raises prompt-injection risk. Overall this is coherent as a QA skill, but its external screenshot-hosting step makes it medium risk rather than benign.

Confidence: 87%Severity: 58%
Audit Metadata
Analyzed At
Apr 23, 2026, 07:59 AM
Package URL
pkg:socket/skills-sh/rogeriochaves%2Fskills%2Fbrowser-qa%2F@35cfd57620a78a0b5741ea6073c15eebb2a19879