browser-automation
Warn
Audited by Socket on May 10, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: The skill’s browser automation capabilities match its stated purpose, but its actual footprint is high risk because it relies on unverifiable local wrapper binaries, processes arbitrary web content with execution capability, and can take autonomous actions on authenticated sites using persistent Chrome profiles. No third-party credential-harvesting endpoint is shown, so this is not confirmed malware, but the trust and account-impact risks are substantial.
Confidence: 86%Severity: 79%
Audit Metadata