agent-browser

Warn

Audited by Socket on Feb 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The agent-browser skill is functionally coherent with its stated purpose (browser automation). It does not contain obvious malicious code or supply-chain download-execute patterns in the provided docs. However, it exposes high-impact capabilities (arbitrary JS eval in page context, network routing/mocking, file upload, state save/load) that can be used to exfiltrate credentials or sensitive files or to manipulate page behavior if misused. Treat usage as medium-risk: require manual review before running with sensitive sessions, avoid passing paths to secret files, encrypt stored state files, and restrict eval/network-route automation to trusted targets.

Confidence: 80%Severity: 75%
Audit Metadata
Analyzed At
Feb 28, 2026, 12:05 PM
Package URL
pkg:socket/skills-sh/ahonn%2Fdotfiles%2Fagent-browser%2F@895c06ee234ff901a532ad61a1648f92022a083b