browser-automation

Fail

Audited by Socket on Mar 18, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS: the skill's capabilities mostly align with browser automation, but its footprint is high-risk because it grants an AI agent broad control over an already-authenticated Chrome profile, including history, bookmarks, network capture, and cookie-backed requests. The install path is plausible for this purpose, yet the combination of side-loaded extension, native bridge, and autonomous web actions makes this a high-impact skill that should only be used with strong user confirmation and verified publisher provenance.

Confidence: 83%Severity: 74%
Audit Metadata
Analyzed At
Mar 18, 2026, 03:45 PM
Package URL
pkg:socket/skills-sh/femto%2Fskills%2Fbrowser-automation%2F@a26be2b16c0fcdfe7c9f3f93ac584111dcabc181