chrome-cdp-live-browser

Warn

Audited by Socket on Mar 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's capabilities match its stated purpose, but that purpose is inherently high-impact: it gives an AI agent broad control over the user's live authenticated browser session. Data flows stay local to Chrome rather than an obvious exfiltration endpoint, so this is not confirmed malware, but the combination of third-party git installation, access to logged-in accounts, cookie/raw CDP visibility, and action-taking in real sessions makes it high risk.

Confidence: 90%Severity: 78%
Audit Metadata
Analyzed At
Mar 15, 2026, 11:57 PM
Package URL
pkg:socket/skills-sh/adisinghstudent%2Fara.so%2Fchrome-cdp-live-browser%2F@63bc6972204f8e9ea706d6842212b1bd8182d072