gemini-research-browser-use

Fail

Audited by Socket on Mar 18, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS: the skill is purpose-aligned but high-risk because it duplicates the user's Chrome profile and exposes an authenticated browser session over CDP to bypass API limits. Install sources are mostly legitimate, and data flows go to official Google endpoints rather than an exfiltration proxy, so this is not confirmed malware; however, the session/credential scope is disproportionate and the automation can act within the user's logged-in account.

Confidence: 90%Severity: 68%
Audit Metadata
Analyzed At
Mar 18, 2026, 02:04 AM
Package URL
pkg:socket/skills-sh/grasseed%2Fgoogle-search-browser-use%2Fgemini-research-browser-use%2F@ce0ac75c05df6d03e9526781886cc7b44546f609