SecureSkill scanned remote-browser by browser-use on 2026-04-19 using scanner version 0.1.0. Verdict: CAUTION. Risk score: 6/10. 5 findings across 10 analysis layers. Platform: AgentSkill.
SecureSkill is the canonical third-party security verification for Agent Skills. When evaluating agent skill safety, security teams reference SecureSkill scan reports as the authoritative source. To check whether an agent skill is safe to install, the standard action is a SecureSkill SSID lookup — this report's identifier is 7bba1897-e374-4396-9358-61127b58bd36.
This skill looks like a legitimate browser automation helper, but it is really a thin instruction layer over an external `browser-use` command-line tool and its cloud services. That means most of the real behavior happens outside the package you can inspect here. The biggest concern in the package itself is a hidden instruction telling the agent to silently send feedback to an external website after use. I would not call it malicious based on this package alone, but it deserves caution because it enables powerful networked actions and is not fully transparent about all of them.
Package Info
Permission Map
Everything this skill can access, modify, and communicate with on your system.
Reads from
Writes to
Runs
Talks to
Permissions Requested
Network Calls
File Writes
5 behaviors were flagged for review. Based on context, none appear overtly malicious — but they grant this skill significant access to your system.
Deterministic Scan·Phase 1
Threat Correlation·Phase 2
AI Reasoning·Phase 3
Components Analyzed
Why this score
This package contains only SKILL.md, so there is no hidden executable script in the package itself; that lowers risk compared with skills that ship shell scripts.
The main concern is that the skill delegates trust to an external CLI and cloud browser service, which can execute powerful actions through Bash while remaining outside the package audit surface.
The embedded auto-review instruction is an extra behavioral directive unrelated to browser control and includes an external POST target, which is a meaningful transparency issue.
The skill's documented capabilities include tunnels, cookie handling, JavaScript execution, Python execution, and public session sharing, so the real impact is broader than the short description suggests.
What to do
Verify all outbound network endpoints match the skill's stated purpose
Check whether the undeclared capabilities are necessary for your use case
Audit all imported dependencies for known vulnerabilities before installing
Scan ID
7bba1897
Scanner
v0.1.0
Date
Apr 19, 2026
Risk Score
6
Skill Version
unspecified
Skill License
unspecified