browser-cdp

Warn

Audited by Socket on Aug 24, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is internally coherent for CDP browser automation, and the install source appears official, but its core capability includes extracting auth tokens/cookies from an existing logged-in browser and routing them through a CLI back to the agent. That is proportionate to the stated purpose yet inherently sensitive, so this is not malware, but it is a high-risk skill that should only be used with strong user awareness and trust in the installed CLI.

Confidence: 87%Severity: 72%
Audit Metadata
Analyzed At
Aug 24, 2026, 03:18 PM
Package URL
pkg:socket/skills-sh/zenstory-ai%2Foh-story-claudecode%2Fbrowser-cdp%2F@6c4bd617abaa7af0dae6fe025f9b07f31be9c2b876712a5bea673f9161c988a2
Security Audit — socket — browser-cdp