browser-cash
Warn
Audited by Socket on Mar 24, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill is internally coherent for remote browser automation and its main network/data flows go to official Browser.cash endpoints, so it is not clearly malicious. However, it is higher-risk than a normal browser helper because it explicitly supports anti-bot bypass, installs unpinned packages at runtime, reads a raw API key from local config, and combines arbitrary web content with exec-based automation.
Confidence: 84%Severity: 63%
Audit Metadata