agent-browser

Fail

Audited by Socket on Mar 2, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

Select Report 1 as the stronger starter due to its comprehensive risk discussion and clearer identification of supply-chain and data-handling concerns. However, it remains prudent to treat the installation from a remote domain without integrity verification as a primary security risk. Recommend tightening the installation workflow (pin or verify installer, use signed binaries), adding explicit data-handling policies for video/screenshot outputs, and clarifying credential/session management in documentation. If the goal is to deliver a hardened assessment, replace this with a new, improved summary that explicitly calls out the download-execute risk and recommends concrete mitigations.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Mar 2, 2026, 09:26 AM
Package URL
pkg:socket/skills-sh/NeverSight%2Fskills_feed%2Fagent-browser%2F@a06a76465f2f721de1d6135ae33463f0a7db1122