functions

Warn

Audited by Socket on Mar 23, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s stated purpose, official Browserbase endpoints, and credential needs are broadly coherent, but the trusted path is undermined by an unpinned runtime install of @browserbasehq/sdk-functions plus evidence that this package was compromised. Because the skill forwards Browserbase API credentials into that package and enables remote browser automation, the overall risk is high even though the documented data flow otherwise looks legitimate.

Confidence: 90%Severity: 88%
Audit Metadata
Analyzed At
Mar 23, 2026, 05:13 PM
Package URL
pkg:socket/skills-sh/quuu%2Fskills%2Ffunctions%2F@5a1154019f60346d1c46e108aa33b4a24d7d2e9b