browser-xterm-interaction

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally consistent as a browser-terminal interaction guide, but it materially expands an agent into arbitrary shell operation through web terminals and includes examples that forward AWS credentials into those sessions. No clear malware or exfiltration endpoint is present, yet the capability and credential-handling scope make it high-impact and medium-high security risk.

Confidence: 87%Severity: 74%
Audit Metadata
Analyzed At
Apr 22, 2026, 10:09 AM
Package URL
pkg:socket/skills-sh/wgpsec%2FAboutSecurity%2Fbrowser-xterm-interaction%2F@526df6999c65742fb0707cc88820785c9fddf210
Security Audit — socket — browser-xterm-interaction