browser-cdp

Warn

Audited by Socket on Apr 8, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated browser-automation purpose matches the capabilities, but the skill’s core trust boundary is an unverifiable local proxy script and it grants high-impact browser control over arbitrary web content. No obvious credential-harvesting endpoint is shown, yet the combination of real-browser actions, arbitrary JS execution, and untrusted web content makes this a high-risk skill rather than a benign low-risk guide.

Confidence: 85%Severity: 74%
Audit Metadata
Analyzed At
Apr 8, 2026, 05:14 PM
Package URL
pkg:socket/skills-sh/linuxhsj%2Fopenclaw-zero-token%2Fbrowser-cdp%2F@21b825427645f7dd8ac2edf7ef0245c7c26a54e3