1c-web-session

Fail

Audited by Socket on Mar 7, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill's stated purpose (1C web client automation and UI-based test data generation) is generally coherent with its capabilities. However, the reliance on clipboard-based input and dynamic code execution (eval via browser_run_code) introduces non-trivial security and safety risks. These data-flow paths could enable data leakage (sensitive values copied to clipboard) and code-injection if untrusted content is supplied. Given the potential for credential exposure and arbitrary code execution surfaces, this skill should be considered SUSPICIOUS to HIGH-RISK in the absence of strict input validation and sandboxing controls. Recommend restricting clipboard usage to non-sensitive test data, enforcing signed/verified scripts for browser_run_code, and auditing logs to ensure no secrets are captured or exfiltrated.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 7, 2026, 11:34 PM
Package URL
pkg:socket/skills-sh/arman-kudaibergenov%2F1c-ai-development-kit%2F1c-web-session%2F@48a527f7240bde6697c8119c43bcf01fbeb7e624