web-scraper
Audited by Socket on Aug 21, 2026
2 alerts found:
AnomalySecuritySUSPICIOUS: the skill is internally coherent for web scraping, but it materially expands into anti-bot evasion, app traffic interception, and reverse-engineering capabilities. Install sources are mostly legitimate and there is no clear credential exfiltration path, yet the external-impact and evasion footprint is broader and riskier than a typical data-collection helper.
No direct evidence of embedded malware/backdoors in the provided fragment. However, the artifact materially increases security and privacy risk by (1) providing mitmproxy-based examples that print and persist raw intercepted request/response data (which can include Authorization headers and personal/confidential information) and (2) offering abuse-enabling guidance (anti-bot/WAF/robots enforcement bypass concepts) plus unverified routing through externally downloaded public proxies. Downstream consumers should treat this as high-risk dual-use content and apply strict safeguards (redaction, access controls, retention limits, and avoid untrusted proxy ingestion).