browser-cdp

Warn

Audited by Socket on Jul 26, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/setup-cdp-chrome.js

This module is not a classic stealth malware/backdoor based on the provided fragment (no eval/dynamic payload execution, no external exfiltration). However, it performs high-impact browser automation: it copies sensitive Chrome authentication/session files into a debug profile and launches Chrome with CDP enabled and broad origin allowance (--remote-allow-origins=*). That combination meaningfully increases the risk profile for anyone who runs the package (or if the package were altered) because it can facilitate session hijacking or further automated access to authenticated browser state, especially in the presence of local attackers or misconfigured access to the CDP port.

Confidence: 74%Severity: 62%
Audit Metadata
Analyzed At
Jul 26, 2026, 10:44 PM
Package URL
pkg:socket/skills-sh/worldwonderer%2Foh-story%2Fbrowser-cdp%2F@928edcfee2947ce64318ca37d9920867c3df361d33e3b18a6be7da877c69dc71
Security Audit — socket — browser-cdp