browser-trace
What this skill does
Capture and analyze browser automation sessions using the Chrome DevTools Protocol (CDP), including firehose traces, screenshots, and DOM dumps. It is a debugging and observability tool for browser au
github/browserbase - Excessive API Usage - 3.7k stars
Threat analysis
Skill info
pkg:github/browserbase/skills@6afe866?skill=browser-traceAssessments (2)
Excessive API Usage
Excessive API Usage via local-llm-review
scripts/bb-capture.mjs
The script uses `runCmd('browse', ['cloud', 'sessions', 'create', ...])` and `runCmd('browse', ['cloud', 'sessions', 'get', ...])` to interact with Browserbase's API. This could be a risk if the API kEnvironment Variable Dependency
Environment Variable Dependency via local-llm-review
scripts/bb-capture.mjs
The script depends on the `BROWSERBASE_API_KEY` environment variable. If this key is not properly secured, it could be a risk. However, this is a standard practice for API authentication and not inherBadge
Add the Anomity scan badge for browser-trace to your README.
How Anomity governs this at runtime
Scan-time vetting tells you what a skill says it will do. Anomity's Endpoint Sensor sees what agents actually do: it discovers skills alongside every other AI artifact on the endpoint, and runtime governance can allow, deny, or log the tool calls a skill triggers. Policy violations route to your SIEM, Slack, email, or Jira, backed by a queryable 90-day audit trail.
Book a 30-minute demo to see your own skill inventory.
Methodology and disputes
Every skill is assessed by the Anomity Skill Intelligence engine against its public source; findings indicate risk patterns, not confirmed exploitation. Maintainer of browser-trace? Report an issue or request a rescan.




