browse
Warn
Audited by Socket on Sep 15, 2026
1 alert found:
SecuritySecurityreferences/permissions.md
MEDIUMSecurityMEDIUM
references/permissions.md
The fragment contains no direct malware or executable malicious payload. It configures an excessively broad permission policy for browser automation, including JavaScript evaluation and access to cookies, authentication, storage, clipboard, network, and file-transfer functions. This creates a meaningful security risk if browse commands or their arguments are attacker-controlled. Least-privilege, command-specific permissions should be used instead of the blanket `Bash(browse:*)` rule.
Confidence: 98%Severity: 72%
Audit Metadata