browse

Warn

Audited by Socket on Mar 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core browsing capability matches the stated purpose, and the install path is mostly consistent with normal developer tooling. However, the skill materially expands agent power by pre-authorizing many Bash-wrapped browser actions, can interact with arbitrary and localhost web content, and creates a high indirect prompt-injection risk from untrusted pages. This is not confirmed malware, but it is a medium/high-risk browsing-and-action skill.

Confidence: 88%Severity: 72%
Audit Metadata
Analyzed At
Mar 15, 2026, 07:31 AM
Package URL
pkg:socket/skills-sh/ulpi-io%2Fskills%2Fbrowse%2F@893cc75058d89bc490d0dc6159d931cb21f397f0