gmaps-leads

Warn

Audited by Socket on Sep 17, 2026

1 alert found:

Security
SecurityMEDIUM
scripts/extract_website_contacts.py

The code is a website contact-information scraper with intended Anthropic-based extraction. It does not show clear malicious intent or malware indicators, but it has meaningful security risks: arbitrary URL fetching with redirects can enable SSRF, scraped data is transmitted to DuckDuckGo and Anthropic, and the output prefix may permit path traversal. The supplied fragment also appears syntactically malformed and may not run as shown.

Confidence: 96%Severity: 72%
Audit Metadata
Analyzed At
Sep 17, 2026, 06:44 PM
Package URL
pkg:socket/skills-sh/aiagentwithdhruv%2Fskills%2Fgmaps-leads%2F@836dbef139268a015baa8162e00802119808d3ac956ed3a28d35c18f6008dfe3