agent-browser

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's purpose and capabilities broadly align with hosted browser automation, and the `infsh` dependency appears to be same-org and officially documented. However, risk is elevated by broad Bash permission, transitive skill installation, hosted remote execution, arbitrary-site browsing with action capability, and untrusted web-content prompt-injection exposure. This looks coherent for its purpose, but it is a high-impact automation skill that should be treated as medium/high security risk rather than benign.

Confidence: 88%Severity: 68%
Audit Metadata
Analyzed At
Mar 18, 2026, 05:26 PM
Package URL
pkg:socket/skills-sh/inference-sh%2Fagent-skills-registry%2Fagent-browser%2F@ac804494a6993a06f7fed50df560f64c1f6dff85