jb-chrome-mcp

Warn

Audited by Socket on May 4, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s purpose and capabilities mostly align, and the main browser-MCP target is an official ChromeDevTools project, but the footprint is still moderately risky. It combines third-party CLI installation, unpinned npx fallback, persisted home-level config, and powerful control over arbitrary existing Chrome tabs, which can expose sensitive browser session data or trigger real actions if the agent is not tightly supervised.

Confidence: 82%Severity: 61%
Audit Metadata
Analyzed At
May 4, 2026, 01:27 PM
Package URL
pkg:socket/skills-sh/bjesuiter%2Fskills%2Fjb-chrome-mcp%2F@b7b49d1476dc2c13078849dd0a98fb8d24e2d021