gologin-local-agent-browser-skill

Warn

Audited by Socket on Mar 31, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is internally aligned with GoLogin local-browser automation, but its footprint is high-risk: it requires an auth token, enables cookie/storage extraction, JS eval, proxy-backed multi-account automation, and unattended batch actions on real websites. No clear malicious exfiltration endpoint is shown, so this is not confirmed malware, but it is a high-impact account automation skill with meaningful abuse and credential/session exposure risk.

Confidence: 83%Severity: 76%
Audit Metadata
Analyzed At
Mar 31, 2026, 01:26 PM
Package URL
pkg:socket/skills-sh/gologinlabs%2Fagent-skills%2Fgologin-local-agent-browser-skill%2F@060f8521d5c36f98cf492b18845d8e0e933bd36e