browser-use

Fail

Audited by Socket on Mar 12, 2026

3 alerts found:

Securityx2Obfuscated File
SecurityMEDIUM
references/ACCOUNT_SAFETY.md

The document is an adversarial operational guide for evading modern anti-bot defenses and scaling account-based browser automation. It contains explicit, actionable instructions to spoof fingerprints, use residential proxies per-account, perform detailed behavioral mimicry, and to employ or distribute native browser modifications. While not executable malware, it materially facilitates abusive operations and increases supply-chain risk if implemented as code or distributed binaries. Treat the presence of this material or any accompanying binaries (Camoufox/Patchright) as high risk: review for TOS/legal issues and inspect binaries for hidden telemetry or backdoors before any use.

Confidence: 80%Severity: 90%
Obfuscated FileHIGH
scripts/actions.py

The code fragment is severely malformed with widespread syntax errors and placeholder remnants, making safe execution impossible in its current state. While the intended design resembles a legitimate browser automation toolkit with powerful capabilities, the corrupted state necessitates a thorough cleanup, validation, and security review before any deployment. There is no concrete malware evidence within intact lines, but the risk profile is elevated due to exposed browser state, external JS evaluation, and the potential for data exfiltration via cookies/storage if inputs are crafted maliciously.

Confidence: 90%
SecurityMEDIUM
SKILL.md

The advice to download and execute external agents (cloakbrowser, Patchright, Camoufox) constitutes a potential command-injection surface if inputs could influence install/run steps or if the binaries accept untrusted payloads. The risk is elevated by auto-download behavior and binary patches from third-party sources.

Confidence: 80%Severity: 75%
Audit Metadata
Analyzed At
Mar 12, 2026, 06:04 PM
Package URL
pkg:socket/skills-sh/yoloshii%2Fbetter-browser-use%2Fbrowser-use%2F@db3b4897a3117bcbf9b7ec3446fcf9a8db6a6c88