browser-xterm-interaction
Warn
Audited by Socket on Apr 22, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill is internally consistent as a browser-terminal interaction guide, but it materially expands an agent into arbitrary shell operation through web terminals and includes examples that forward AWS credentials into those sessions. No clear malware or exfiltration endpoint is present, yet the capability and credential-handling scope make it high-impact and medium-high security risk.
Confidence: 87%Severity: 74%
Audit Metadata