browser-login
Warn
Audited by Socket on Sep 15, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill’s main behavior—capturing and storing reusable session cookies—fits its stated purpose, but it handles extremely sensitive auth material, routes storage through an unpinned external CLI invocation, and leaves parts of the vault/mount workflow underspecified. This looks more like a high-risk auth automation skill than confirmed malware.
Confidence: 81%Severity: 62%
Audit Metadata