x9-browser-session

Warn

Audited by Socket on Sep 5, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s purpose and most capabilities are coherent for authenticated browser automation, and its official chrome-devtools-mcp setup is broadly consistent. The main risk is disproportionate trust in an unverified fallback CLI (agent-browser via agent-edge) that attaches to a logged-in browser profile and can access sensitive session data; combined with authenticated browser control, this raises overall security risk even without clear malicious intent.

Confidence: 85%Severity: 76%
Audit Metadata
Analyzed At
Sep 5, 2026, 11:11 AM
Package URL
pkg:socket/skills-sh/xonika9%2Fagent-skills%2Fx9-browser-session%2F@69822dd4bae37fefd6bb02f6e21d76d0203d4f33a740b76bd0810adb3c0a45cd
Security Audit — socket — x9-browser-session