browse

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Security
SecurityMEDIUM
references/permissions.md

The fragment contains no direct malware or executable malicious payload. It configures an excessively broad permission policy for browser automation, including JavaScript evaluation and access to cookies, authentication, storage, clipboard, network, and file-transfer functions. This creates a meaningful security risk if browse commands or their arguments are attacker-controlled. Least-privilege, command-specific permissions should be used instead of the blanket `Bash(browse:*)` rule.

Confidence: 98%Severity: 72%
Audit Metadata
Analyzed At
Sep 15, 2026, 12:05 PM
Package URL
pkg:socket/skills-sh/ulpi-io%2Fskills%2Fbrowse%2F@e4fdd5349fd9c270fe286a504ac3ecda86fe1f0e8d0fb83d570b0af7731e17ce
Security Audit — socket — browse