browser-automation

Warn

Audited by Socket on Mar 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core browser automation capabilities match the stated purpose, and the referenced dependency appears to be an official Microsoft Playwright MCP project rather than an unknown third-party payload. However, the skill gives an agent action-capable access to arbitrary websites, including form submission and script execution, which creates meaningful indirect prompt-injection and autonomy risk if used on untrusted pages or without explicit user approval for consequential actions.

Confidence: 87%Severity: 56%
Audit Metadata
Analyzed At
Mar 21, 2026, 02:45 AM
Package URL
pkg:socket/skills-sh/serenorg%2Fseren-skills%2Fbrowser-automation%2F@e6a071a3c72dc5eb04bd0a416d405b4a83331afd