What the reviewer found
Browser-automation skill that clones your real Chrome profile (to reuse your logged-in session) and drives Gemini/Qwen via Chrome DevTools Protocol on localhost:9222; the curl is a local CDP status check, not remote-code execution, and the rm -rf only clears its own /tmp/chrome-ai-profile clone. Worth knowing: it does use your live authenticated browser session to query two external AI web services.
network— calls the vendor’s API
What was read
The file as it ships in JWCodeWrote/Agent_Skills_Plugin:
AI-search-browser-use-main/SKILL.md
What the static scan said
The scan flagged 4things. The reviewer kept 2 and dismissed 2 as false.
SC2Downloads and executes remote code — false positiveRMRecursive force delete — false positiveNETMakes network calls — realSHRuns shell commands — real
How this review was made
Sonnet 5 read the files above on 7 September 2026 and answered three questions: is it dangerous to whoever installs it, is each scanner finding real, and what should the installer know. The verdict is bound to the file's hash; when the file changes, it is scanned afresh and reviewed again. A script that changes while the definition does not is not re-reviewed — that is a known gap. How the scan and the review work.