browser-automation

Fail

Audited by Socket on Mar 19, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS: the skill's capabilities mostly align with browser automation, but its footprint is high-risk because it grants an AI agent broad control over an already-authenticated Chrome profile, including history, bookmarks, network capture, and cookie-backed requests. The install path is plausible for this purpose, yet the combination of side-loaded extension, native bridge, and autonomous web actions makes this a high-impact skill that should only be used with strong user confirmation and verified publisher provenance.

Confidence: 83%Severity: 74%
Audit Metadata
Analyzed At
Mar 19, 2026, 05:19 PM
Package URL
pkg:socket/skills-sh/openclaw%2Fskills%2Fbrowser-automation%2F@b129b65bce02b78daf381b9dc1e24c4e6429671c