browser-login

Warn

Audited by Socket on Jun 13, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s purpose and capabilities mostly align, but it handles highly sensitive session cookies, extracts them via browser instrumentation, and stores reuse handles through an unpinned external CLI. This is proportionate to a browser-login skill, yet the combination of session capture, persistence, and mutable runtime dependency makes it medium-to-high security risk rather than benign.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 13, 2026, 01:23 PM
Package URL
pkg:socket/skills-sh/ruvnet%2Fclaude-flow%2Fbrowser-login%2F@e4fcea74636964073a96b6a67a8d739950f734ffa70129b72eee6405634ab003
Security Audit — socket — browser-login