browserstack-local

npm

Is browserstack-local safe to use?

The latest brin safety scan flagged browserstack-local v1.5.8 with risk indicators that warrant review. 2 known CVE vulnerabilities. Trust score: 65/100. Review the findings below before use. This is an automated assessment and may contain errors.

Install (safety-checked)

browserstack-local Has Warnings

Warnings detected due to potential concerns

warning
CVEs

2

Threats

0

Install Scripts

0

Risk Indicators

  • GHSA-g4w6-c99w-4wh7: UNKNOWN
  • Can spawn child processes

browserstack-local CVE Vulnerabilities (2)

BrowserStack Local vulnerable to Command Injection through logfile variable

GHSA-g4w6-c99w-4wh7CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P

BrowserStack Local vulnerable to Command Injection through logfile variable

brin Recommendations

  • This package has warnings detected. Evaluate the specific concerns before proceeding.

Install with brin add browserstack-local to automatically apply these checks before installation.

This is an automated, point-in-time assessment and may contain errors. Findings are risk indicators, not confirmed threats. Security posture may change over time. Maintainers can dispute findings via the brin review process.

browserstack-local Capabilities & Permissions

What browserstack-local can access when installed. Review these capabilities before using with AI agents like Cursor, Claude Code, or Codex.

Network Access

This package makes network requests.

hub.browserstack.comwww.browserstack.comwww.google.com
Protocols: http, https

Filesystem Access

Reads and writes to the filesystem.

.env (rw).env (rw).env (rw)package.json (rw)/etc/ (rw)/home/ (rw).env (rw)package.json (rw)+4 more

Process Spawning

This package can spawn child processes.

Environment Variables

Accesses the following environment variables.

BINARY_DOWNLOAD_ERROR_MESSAGEBINARY_DOWNLOAD_FALLBACK_ENABLEDBINARY_DOWNLOAD_SOURCE_URLBROWSERSTACK_ACCESS_KEYBROWSERSTACK_LOCAL_DEBUG_GZIPBROWSERSTACK_USERNAMEUSER_AGENT

AGENTS.md for browserstack-local

Good instructions lead to good results. brin adds browserstack-local documentation to your AGENTS.md so your agent knows how to use it properly—improving both safety and performance.

brin init

Vercel's research: 100% accuracy with AGENTS.md vs 53% without →

browserstack-local Documentation & Source Code

For the full browserstack-local README, API documentation, and source code, visit the official package registry.

Frequently asked questions about browserstack-local safety

Weekly Downloads

560.3K

Version

1.5.8

License

MIT

Other Versions

Last Scanned

Feb 1, 2026

Trust Score

65/100·Legitimacy signals, not safety

CVEs (2)

CVE-2025-57283

BrowserStack Local vulnerable to Command Injection through logfile variable

GHSA-g4w6-c99w-4wh7

BrowserStack Local vulnerable to Command Injection through logfile variable

Capabilities

Network

Connects to: hub.browserstack.com, www.browserstack.com, www.google.com

Filesystem

Reads & Writes files

Process

Spawns child processes

Environment

Accesses: BINARY_DOWNLOAD_ERROR_MESSAGE, BINARY_DOWNLOAD_FALLBACK_ENABLED, BINARY_DOWNLOAD_SOURCE_URL...

Is browserstack-local Safe? | PyPI Safety Scan - brin