The skill is mostly a disclosed browser automation guide, but it grants broad command/file authority and handles browser sessions with overly broad activation rules and weak safeguards.
Review this skill carefully before installing. Use it only for browser automation tasks you explicitly authorize, avoid running it on unrelated local files or shell tasks, and treat cookies, saved auth files, proxy settings, webhooks, and multi-account workflows as sensitive. Prefer a pinned and trusted agent-browser package source, and do not share or export session state unless you understand where it will be stored and who can access it.