screencast

Warn

Audited by Socket on Aug 11, 2026

1 alert found:

Anomaly
AnomalyLOW
lib/agentbrowser.mjs

This code is an automation/control wrapper whose main security exposure is (1) executing an environment-specified external binary (SCREENCAST_AB_BIN) without validation, and (2) performing browser-context JavaScript evaluation via capture(['eval', js]) to inject a fullscreen flash overlay. There is no direct evidence of data theft or malware persistence in the shown fragment, but the eval primitive and process-selection trust boundary elevate security risk if any upstream inputs or environment variables are attacker-influenced.

Confidence: 56%Severity: 60%
Audit Metadata
Analyzed At
Aug 11, 2026, 08:23 AM
Package URL
pkg:socket/skills-sh/vesely%2Fskills%2Fscreencast%2F@8eab8ac7138c8ac5f21e0db6b8d070b5f70dea6eb5e0dbac7ba754525174c3cf
Security Audit — socket — screencast