steel-browser

Warn

Audited by Socket on Apr 6, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s capabilities largely match its stated purpose as a cloud browser integration, and the publisher/source relationship appears coherent. The main concerns are the pipe-to-shell installer, third-party cloud handling of browsing/session data and credentials, explicit stealth/CAPTCHA-bypass features, and autonomous real-world web actions. This looks more like a high-risk browser automation skill than confirmed malware.

Confidence: 87%Severity: 62%
Audit Metadata
Analyzed At
Apr 6, 2026, 05:00 PM
Package URL
pkg:socket/skills-sh/steel-dev%2Fcli%2Fsteel-browser%2F@34da600b516ed24601653cf31b721b3e7daa3524