browser-automation
Warn
Audited by Socket on Jul 29, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the stated browser-automation purpose matches most capabilities, but the skill’s true runtime is hidden inside unverified local binaries and it enables high-impact actions on authenticated sites. No direct credential exfiltration or malicious endpoint is shown, yet the combination of opaque executables, persistent session reuse, and arbitrary web-driven actioning makes the overall risk high enough to treat cautiously.
Confidence: 84%Severity: 78%
Audit Metadata