anything-analyzer-cdp
Warn
Audited by Socket on Apr 13, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s capture capabilities match its stated purpose, but the footprint is high-risk: it records full browser traffic, cookies, storage, and auth flows, then forwards them to external AI services or arbitrary custom endpoints. The install path is conventional source-based JS tooling, yet the publisher/repo mismatch and the exfiltration of sensitive session data make this disproportionate for a generic AI agent skill.
Confidence: 89%Severity: 86%
Audit Metadata