browser-automation
Warn
Audited by Socket on Mar 21, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The core browser automation capabilities match the stated purpose, and the referenced dependency appears to be an official Microsoft Playwright MCP project rather than an unknown third-party payload. However, the skill gives an agent action-capable access to arbitrary websites, including form submission and script execution, which creates meaningful indirect prompt-injection and autonomy risk if used on untrusted pages or without explicit user approval for consequential actions.
Confidence: 87%Severity: 56%
Audit Metadata