web-browser

Warn

Audited by Socket on Mar 4, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/eval.js

This tool provides powerful debugging capabilities by evaluating arbitrary code within a live browser page context via CDP. While useful for debugging, it poses significant security risks if exposed to untrusted input or deployed in insecure environments due to lack of sandboxing, data access within the page, and potential manipulation of page state. No hardcoded secrets are evident, but the core capability should be tightly access-controlled or sandboxed. Improved safety would include input validation, restricted API surface, and a sandboxed evaluation environment.

Confidence: 68%Severity: 60%
Audit Metadata
Analyzed At
Mar 4, 2026, 02:48 AM
Package URL
pkg:socket/skills-sh/mitsuhiko%2Fagent-stuff%2Fweb-browser%2F@280d41c06d37237ac3a27152f16032d1b3ad8fd2