web-browser

Fail

Audited by Socket on Mar 2, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The package/document fragment describes legitimate and useful browser automation functionality but relies on runtime download-and-execute patterns (npx) and broad execution permissions that create moderate-to-high supply-chain and operational risks. The main threats are: execution of malicious or typosquatted npm packages, transitive dependency compromise, and accidental capture/exfiltration of credentials or scraped data. Recommended mitigations before use: pin package names to specific vetted versions, vendor or preinstall required CLI tools instead of using npx, run automation in isolated environments (containers, VMs) with restricted network egress and limited filesystem access, avoid entering real credentials unless the runtime integrity is verified, audit any sub-skill/template code and transitive dependencies, and add provenance checks (checksums/signatures) and logging redaction policies.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 2, 2026, 11:03 AM
Package URL
pkg:socket/skills-sh/nikhilmaddirala%2Fgtd-cc%2Fweb-browser%2F@489246d0c47d2bf244833a323817dba29a4ef0b8