cm-browse-9ffdec — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited cm-browse-9ffdec (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Full runbook: docs/browse-daemon.md (install Chromium, token, troubleshooting).
cm browse + cm qa-visual.export CM_BROWSE_TOKEN="$(openssl rand -hex 24)"
cm browse start --port 17395 --token "$CM_BROWSE_TOKEN"POST /session/start body { "headless": true }POST /navigate { "url": "https://…" }POST /refs/refresh — assigns data-cm-ref to interactive nodes; use @e1 style refs.POST /click { "ref": "e1" }POST /fill { "ref": "e2", "value": "text" }GET /screenshot — PNGGET /console / GET /network — ring bufferscm qa-visual --url … calls the daemon locally.cm-canary / cm-safe-deploy for ship verification.~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.