chrome-cdp

Warn

Audited by Socket on May 7, 2026

1 alert found:

Security
SecurityMEDIUM
scripts/inject.mjs

This module is an automation-style CDP injector that will load and execute a remote JavaScript URL in a target browser tab via Runtime.evaluate + DOM <script> injection. While it contains no explicit exfiltration or persistence logic in the shown fragment, its design is inherently high-impact because any untrusted or attacker-controlled --url results in arbitrary page-context script execution. The absence of URL validation/allowlisting and reliance on a user-supplied CDP endpoint materially increase misuse risk.

Confidence: 68%Severity: 72%
Audit Metadata
Analyzed At
May 7, 2026, 03:11 AM
Package URL
pkg:socket/skills-sh/hixuanxuan%2Fbrowser-automation%2Fchrome-cdp%2F@53bda92af37657378030669c5b0f0179abeeceed