browser-use
Warn
Audited by Socket on Apr 24, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill is mostly aligned with its stated browser-automation purpose and uses official Browser Use API endpoints, but it introduces a VM0 connector/broker layer for credential handling and enables high-impact autonomous web actions on arbitrary sites. This is not confirmed malware and lacks malicious install or exfiltration patterns, but the third-party credential mediation plus agentic browser control make it a medium-risk skill.
Confidence: 84%Severity: 58%
Audit Metadata