gmaps-leads
Warn
Audited by Socket on Sep 17, 2026
1 alert found:
SecuritySecurityscripts/extract_website_contacts.py
MEDIUMSecurityMEDIUM
scripts/extract_website_contacts.py
The code is a website contact-information scraper with intended Anthropic-based extraction. It does not show clear malicious intent or malware indicators, but it has meaningful security risks: arbitrary URL fetching with redirects can enable SSRF, scraped data is transmitted to DuckDuckGo and Anthropic, and the output prefix may permit path traversal. The supplied fragment also appears syntactically malformed and may not run as shown.
Confidence: 96%Severity: 72%
Audit Metadata