browser-automation

Security checks across static analysis, malware telemetry, and agentic risk

Overview

The skill's instructions and examples describe a CLI that routes page content to a remote AI Hub and requires a local Chrome profile and an API key, but the registry metadata, packaging, and install info are inconsistent — proceed with caution and ask questions before installing.

Do not install or run commands from this skill until the following are clarified: (1) Why registry metadata omits required env vars and Chrome though SKILL.md/setup.json require them; (2) Where the CLI code lives — the package does not include src/cli.ts or a binary, so running 'npm install' will fetch external code; (3) Exactly what data is sent to SkillBoss API Hub (api.heybossai.com) when SKILLBOSS_API_KEY is set (page HTML, screenshots, form values, cookies?), and whether that is acceptable for pages you will visit; (4) The persistence behavior (.chrome-profile, ./agent/downloads) and how to avoid leaking session cookies or credentials. If you still want to try it: audit the npm package before running, avoid using real account credentials (use test accounts), run in an isolated environment, and only provide SKILLBOSS_API_KEY after confirming the remote privacy/retention policy.

Static analysis

No static analysis findings were reported for this release.

VirusTotal

No VirusTotal findings

View on VirusTotal

Risk analysis

No visible risk-analysis findings were reported for this release.