chrome-devtools

Warn

Audited by Socket on Mar 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This codebase/documentation describes a legitimate Puppeteer-based automation toolkit. I found no explicit malicious code, obfuscated payloads, or embedded credentials in the provided material. The primary risks are inherent to the tool's capabilities: executing arbitrary page JS (evaluate.js), loading arbitrary remote pages (which can themselves exfiltrate data), and reliance on upstream npm/Chrome binary downloads (supply-chain surface). Treat inputs and target URLs as untrusted, isolate automation runs (ephemeral profiles, network restrictions), and pin/verify dependencies to mitigate supply-chain concerns.

Confidence: 98%Severity: 75%
Audit Metadata
Analyzed At
Mar 1, 2026, 06:32 PM
Package URL
pkg:socket/skills-sh/mrgoonie%2Fxxxnaper%2Fchrome-devtools%2F@a6c6853a2b644ae93efbf1ace77222eeb8bb614f