pinchtab

Warn

Audited by Socket on Sep 19, 2026

1 alert found:

Security
SecurityMEDIUM
references/api.md

This fragment documents a highly privileged browser-automation API. It contains no direct evidence of malware, but deployment security is critical: unauthenticated or weakly authorized access could permit session-cookie exposure, network credential leakage, arbitrary JavaScript execution, SSRF, local file reads or writes, uploads, and automated challenge bypass. The fragment alone cannot establish that these vulnerabilities exist in the implementation.

Confidence: 97%Severity: 72%
Audit Metadata
Analyzed At
Sep 19, 2026, 11:33 PM
Package URL
pkg:socket/skills-sh/xianmingyao%2Fopenclaw-cayson%2Fpinchtab%2F@ce25a4430f91f6abab2f7f03e12bf3aec2e5a5849fc5312daa67890cfb72d4a8
Security Audit — socket — pinchtab