reflex-browser

Warn

Audited by Socket on Mar 14, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's stated purpose matches browser automation, but its core functionality depends on a globally installed CLI fetched from a private custom registry with no source or release verification in the skill. That makes install trust the dominant risk; the footprint is plausible, yet insufficiently transparent for a benign classification.

Confidence: 84%Severity: 82%
Audit Metadata
Analyzed At
Mar 14, 2026, 03:52 AM
Package URL
pkg:socket/skills-sh/fruffel%2Freflex-browser-skill%2Freflex-browser%2F@a11761fba3cf3061ab83fc77b258048d046f2cb8