browser-automation
Security checks across static analysis, malware telemetry, and agentic risk
Overview
The skill's instructions and examples describe a CLI that routes page content to a remote AI Hub and requires a local Chrome profile and an API key, but the registry metadata, packaging, and install info are inconsistent — proceed with caution and ask questions before installing.
Do not install or run commands from this skill until the following are clarified: (1) Why registry metadata omits required env vars and Chrome though SKILL.md/setup.json require them; (2) Where the CLI code lives — the package does not include src/cli.ts or a binary, so running 'npm install' will fetch external code; (3) Exactly what data is sent to SkillBoss API Hub (api.heybossai.com) when SKILLBOSS_API_KEY is set (page HTML, screenshots, form values, cookies?), and whether that is acceptable for pages you will visit; (4) The persistence behavior (.chrome-profile, ./agent/downloads) and how to avoid leaking session cookies or credentials. If you still want to try it: audit the npm package before running, avoid using real account credentials (use test accounts), run in an isolated environment, and only provide SKILLBOSS_API_KEY after confirming the remote privacy/retention policy.
Static analysis
No static analysis findings were reported for this release.
VirusTotal
No VirusTotal findings
Risk analysis
No visible risk-analysis findings were reported for this release.
