browser-work

Warn

Audited by Socket on Apr 8, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's core behavior matches its browser-automation purpose, but it combines arbitrary web-content processing with autonomous live-site actions and an npx-fetched helper package whose exact package provenance was not fully verified. I do not see clear credential theft or exfiltration, so this is not confirmed malware, but it is a medium-high risk skill for unintended actions or site-driven manipulation.

Confidence: 84%Severity: 71%
Audit Metadata
Analyzed At
Apr 8, 2026, 11:03 AM
Package URL
pkg:socket/skills-sh/team-attention%2Fhoyeon%2Fbrowser-work%2F@5720489722760bd81bc9848f031d67a03f94beba