agent-browser

Fail

Audited by Socket on Feb 16, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The provided SKILL.md documents a legitimate browser automation CLI with powerful primitives expected in such tools. There is no evidence of embedded malicious code in this documentation. However, multiple documented features substantially increase the risk surface: loading arbitrary browser extensions, saving/restoring full session state to disk, passing credentials in proxy URLs, routing through third-party provider services, and executing arbitrary JavaScript. These are not intrinsically malicious but can be abused or misconfigured to exfiltrate credentials or page data. I recommend reviewing the actual implementation, any referenced templates and extensions, and operational defaults (encryption of state files, validation of extensions, secure default providers) before using this tool in sensitive environments.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 16, 2026, 11:06 AM
Package URL
pkg:socket/skills-sh/kunhai-88%2Fskills%2Fagent-browser%2F@9eb0f2aab6311af8a7612511b9a143c11ecec3c9