Flagged by auditors
Independent security partners scan this skill's files for malicious content, prompt injection and risky patterns. Verdicts below come from the skills.sh audit program; each partner links to its full report.
Gen Agent Trust Hub
warnThe skill provides comprehensive browser automation and data extraction capabilities using the opencli tool. Security risks include the potential exfiltration of sensitive local files via the upload command, exposure of network credentials and session tokens through traffic capture, and dynamic JavaScript execution within the browser context. It also creates a significant surface for indirect prompt injection from untrusted web content.
Socket
passNo alerts
Snyk
failRisk: HIGH · 2 issues
ZeroLeaks
passScore: 93/100 · 2 sections analyzed