browser-testing-with-devtools
Warn
Audited by Socket on May 16, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill’s purpose and capabilities are largely coherent and it includes strong safety boundaries against browser-content prompt injection and credential access. The main issue is install trust: the documented `npx @anthropic/chrome-devtools-mcp@latest` does not match the official ChromeDevTools package name found in public docs, and it is unpinned runtime execution. That mismatch makes provenance uncertain and elevates risk, but there is no evidence of credential harvesting, exfiltration, or malicious intent in the skill itself.
Confidence: 92%Severity: 58%
Audit Metadata