chrome-devtools-cli

Warn

Audited by Socket on Mar 11, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill presents a coherent capability: automating Chrome DevTools via a CLI to perform browser actions and collect diagnostics. However, the footprint is not fully trustworthy due to unverifiable binaries (chrome-devtools-mcp) and lack of explicit, verifiable install sources. This elevates risk around supply-chain integrity and potential unintended data exposure. The data flows described are primarily local to the browser and user machine, with outputs written to files; no explicit credential handling is evident. Overall, suspicious due to unverifiable binary distribution; classify as SUSPICIOUS with high caution until provenance and install checks are provided.

Confidence: 98%Severity: 75%
Audit Metadata
Analyzed At
Mar 11, 2026, 09:52 AM
Package URL
pkg:socket/skills-sh/ChromeDevTools%2Fchrome-devtools-mcp%2Fchrome-devtools-cli%2F@ebc8b19d29cbcbb471d292cda03722ebdbb99482