browser-use

Fail

Audited by Socket on Feb 16, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The documented package enables legitimate browser automation but exposes high-risk capabilities: arbitrary JS/Playwright execution and persistent shared browser contexts that preserve authentication state. Without documented authentication, network-binding restrictions, or caller controls, the MCP HTTP endpoint presents a significant attack surface enabling credential theft, internal data access, and data exfiltration. Recommend requiring secure defaults (bind to localhost, require authentication tokens), disabling shared contexts for untrusted callers, auditing/logging, and restricting arbitrary-code execution (use a safe, whitelisted command set) before deploying in environments with sensitive data.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 16, 2026, 01:06 PM
Package URL
pkg:socket/skills-sh/salmanferozkhan%2Fcloud-and-fast-api%2Fbrowser-use%2F@687e7e845a8786b89ea1fd8690a39768dfd41fda