agent-browser
Warn
Audited by Socket on Sep 17, 2026
1 alert found:
AnomalyAnomalyreferences/commands.md
LOWAnomalyLOW
references/commands.md
No direct evidence of malware is present in the provided fragment because it is documentation rather than executable code. However, it describes a high-privilege browser automation interface that can execute arbitrary in-page JavaScript (including via base64/stdin), modify and persist sensitive browser auth/state, intercept/mock network traffic, load arbitrary extensions, and weaken transport security. The security concern is misuse/abuse potential and risk escalation in compromised or untrusted automation contexts.
Confidence: 62%Severity: 60%
Audit Metadata