smooth-browser

Warn

Audited by Socket on Mar 13, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is broadly aligned with its stated purpose and uses an official-looking PyPI package from the same org, so it is not overtly malicious. However, it grants a third-party browser automation service access to API credentials, uploaded local files, browsing sessions, persistent cookies, and potentially sensitive authenticated workflows; combined with autonomous web actions and arbitrary-site browsing, this creates meaningful security risk even though the data flows appear vendor-consistent rather than deceptive.

Confidence: 87%Severity: 61%
Audit Metadata
Analyzed At
Mar 13, 2026, 10:00 AM
Package URL
pkg:socket/skills-sh/circlemind-ai%2Fsmooth-sdk%2Fsmooth-browser%2F@864f74c74e161fb77587209c90befab0b32d5a13