You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
adds a complete keychain-context-sync skill for migrating a macOS Chrome profile into a Browserbase Context without source CDP
snapshots and archives durable profile state including site storage, service workers, bookmarks, history, preferences, and extension state
requests Chrome Safe Storage through the native macOS Keychain consent flow and decrypts cookie values in memory
implements Chrome's macOS v10 PBKDF2/AES decryption and schema-v24 host-digest verification
excludes disposable caches, runtime locks, tab-restore data, raw cookie/login databases, and saved passwords
envelope-encrypts the profile ZIP and uploads it through the Browserbase Context API
starts a persistent destination session and imports non-expired cookies using the destination browser's encryption environment
supports inspect-only validation, new or existing Contexts, domain filters, Verified mode, and residential proxies
Why
cookie-sync requires a live source CDP connection and only transfers cookies. This workflow supports consented access to a closed Chrome profile and migrates broader disk-backed browser state alongside its cookies.
The raw macOS cookie database cannot be copied directly into Browserbase's Linux runtime because encrypted values are bound to the source user's Keychain. The combined flow decrypts locally, uploads the profile without non-portable credential databases, and imports cookies in memory at the destination.
Safety and impact
macOS—not the script—collects Keychain authorization
the script never requests the user's login password directly
Safe Storage secrets, derived keys, cookie contents, profile metadata, and signed upload URLs are never logged or persisted
temporary database snapshots and archive files are removed after use
--inspect-only performs no Browserbase mutation; --upload is explicit
live Chrome profiles are rejected unless the user explicitly passes --allow-live-copy
Next steps: Take a moment to review the security alert above. Review
the linked package source code to understand the potential risk. Ensure the
package is not malicious before proceeding. If you're unsure how to proceed,
reach out to your security team or ask the Socket team for help at
support@socket.dev.
Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.
Mark the package as acceptable risk. To ignore this alert only
in this pull request, reply with the comment
@SocketSecurity ignore npm/@browserbasehq/stagehand@3.7.1. You can
also ignore all packages with @SocketSecurity ignore-all.
To ignore an alert for all future pull requests, use Socket's Dashboard to
change the triage state of this alert.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What changed
keychain-context-syncskill for migrating a macOS Chrome profile into a Browserbase Context without source CDPChrome Safe Storagethrough the native macOS Keychain consent flow and decrypts cookie values in memoryv10PBKDF2/AES decryption and schema-v24 host-digest verificationWhy
cookie-syncrequires a live source CDP connection and only transfers cookies. This workflow supports consented access to a closed Chrome profile and migrates broader disk-backed browser state alongside its cookies.The raw macOS cookie database cannot be copied directly into Browserbase's Linux runtime because encrypted values are bound to the source user's Keychain. The combined flow decrypts locally, uploads the profile without non-portable credential databases, and imports cookies in memory at the destination.
Safety and impact
--inspect-onlyperforms no Browserbase mutation;--uploadis explicit--allow-live-copyValidation