browser

Fail

Audited by Socket on Feb 14, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
eval.js

This script intentionally exposes a powerful remote-eval capability into the first open browser page. The file itself shows no signs of obfuscation or embedded malicious payloads, but its functionality is inherently dangerous: untrusted input results in code execution within the page context, allowing data access and exfiltration or actions as the page. Treat this as a dangerous tool to be used only in trusted, controlled environments; otherwise restrict access or replace with safer, narrowly-scoped interfaces.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 14, 2026, 01:44 PM
Package URL
pkg:socket/skills-sh/ajianaz%2Fskills-collection%2Fbrowser%2F@a5cdfea7835d3a76201ad5b45547932027339b55