chrome-devtools

Fail

Audited by Socket on Feb 27, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

No explicit malicious code or hardcoded credentials are present in the provided manifest and documentation. The primary concern is functionality: the skill exposes powerful primitives (arbitrary in-page JS execution, network/console/snapshot access, and local-file upload) that can be misused to exfiltrate data or perform unwanted actions if used against untrusted content or without strict operational controls. Treat this component as sensitive: enforce explicit user consent for each navigation and risky operation, restrict evaluate_script usage, implement URL whitelisting or prompt-based approval, sanitize diagnostic outputs before returning them, and avoid unattended autonomous operation with this skill.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 27, 2026, 02:23 AM
Package URL
pkg:socket/skills-sh/tech-leads-club%2Fagent-skills%2Fchrome-devtools%2F@29950681403a94b839a4dbd91db0dfad191cc15b