browser-tools

Fail

Audited by Socket on Mar 1, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The browser-tools suite is technically coherent with its stated purpose of agent-assisted browser automation and data extraction. The primary security concern is environmental: remote debugging on port 9222 can expose browser session data if the debugging interface is accessible to untrusted actors. The code paths described (DOM reads, cookie inspection, content extraction, and JS evaluation) are expected for a frontend testing/automation tool and do not themselves implement external data sinks or credential harvesting. Overall risk is moderate and proportional to purpose; treat the remote-debugging exposure as the main risk factor and ensure proper access controls, network segmentation, and port restrictions.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 1, 2026, 05:12 AM
Package URL
pkg:socket/skills-sh/winsorllc%2Fupgraded-carnival%2Fbrowser-tools%2F@2ece87d8b0ffe4cf9e565580a63c4d77937dcf80