browser-cdp
Warn
Audited by Socket on Aug 24, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill is internally coherent for CDP browser automation, and the install source appears official, but its core capability includes extracting auth tokens/cookies from an existing logged-in browser and routing them through a CLI back to the agent. That is proportionate to the stated purpose yet inherently sensitive, so this is not malware, but it is a high-risk skill that should only be used with strong user awareness and trust in the installed CLI.
Confidence: 87%Severity: 72%
Audit Metadata