agent-browser

Fail

Audited by Socket on Mar 1, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The agent-browser manifest describes legitimate browser automation functionality with typical input/output and state-persistence features. While the intended use is benign, the combination of credentials in auth.json, cookies/localStorage, and environment-supplied encryption keys creates meaningful at-rest and access-control risks. Appropriate safeguards—such as strict file permissions, encryption key management, least-privilege execution, and auditable session handling—are essential for secure deployment. Overall, the design is sound for its purpose but warrants rigorous operational security controls.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Mar 1, 2026, 01:36 PM
Package URL
pkg:socket/skills-sh/TinyAGI%2Ftinyclaw%2Fagent-browser%2F@634a477490f94cc15da70a7ea148deaf476e90d8