anything-analyzer-cdp

Warn

Audited by Socket on Apr 13, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s capture capabilities match its stated purpose, but the footprint is high-risk: it records full browser traffic, cookies, storage, and auth flows, then forwards them to external AI services or arbitrary custom endpoints. The install path is conventional source-based JS tooling, yet the publisher/repo mismatch and the exfiltration of sensitive session data make this disproportionate for a generic AI agent skill.

Confidence: 89%Severity: 86%
Audit Metadata
Analyzed At
Apr 13, 2026, 05:33 PM
Package URL
pkg:socket/skills-sh/Aradotso%2Ftrending-skills%2Fanything-analyzer-cdp%2F@bd639664012e2bd641719cbbc0a9bc918eced451