chrome-devtools

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/evaluate.js

This script intentionally executes user-provided JavaScript inside a browser page context (via page.evaluate + eval) and navigates to user-provided URLs without validation. The code itself does not contain obvious malware, obfuscation, or hardcoded secrets, but it provides a powerful primitive that can be abused to read sensitive page data or perform exfiltration when given untrusted input. Treat use of this tool as high-risk if scripts or URLs can be influenced by untrusted parties; otherwise it is expected functionality for a browser automation CLI.

Confidence: 90%Severity: 60%
Audit Metadata
Analyzed At
Mar 18, 2026, 05:29 PM
Package URL
pkg:socket/skills-sh/duc01226%2Feasyplatform%2Fchrome-devtools%2F@eca0a0f387a9f0a61aaf0c4f3a74b9b355a46764