agent-browser

Warn

Audited by Socket on Mar 3, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill documentation for agent-browser coherently supports its intended use for advanced, stateful browser automation with session persistence, state management, and network interception. However, it introduces credential-related risks due to handling of JWT cookies and tokens, and relies on external tooling with potential supply-chain drift if version pinning is not enforced. The primary risk drivers are credential exposure via state/logs and the potential misconfiguration of environment paths (Nix/Chromium) that could affect executables. Overall, the security posture is medium: non-malicious by design but susceptible to credential leakage and configuration-related risks. Recommended mitigations include pinning tool versions, securing state/cookie storage (encryption or restricted access), and documenting secure handling practices for tokens and logs.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 3, 2026, 02:33 AM
Package URL
pkg:socket/skills-sh/NumberOne-AI%2Fmachina-meta%2Fagent-browser%2F@4070432b2ff871141b236e23a71cb8327b7e9d06