Chrome Bridge Automation

Warn

Audited by Socket on Mar 20, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's browser automation behavior matches its stated purpose, but it carries material security risk because it operates inside the user's real authenticated Chrome session and may send screenshot-derived data to configurable external model endpoints. The npm install path is relatively normal, yet the combination of live-session control, arbitrary website content, and third-party model routing makes this a high-impact automation skill that needs careful user oversight.

Confidence: 82%Severity: 69%
Audit Metadata
Analyzed At
Mar 20, 2026, 01:02 AM
Package URL
pkg:socket/skills-sh/Hainrixz%2Fclaude-webkit%2Fchrome-bridge-automation%2F@ccb8931a0c91186a0980f7ce9d3b94234fc12af3