scrapling
Pass
Audited by Gen Agent Trust Hub on Jul 8, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill uses shell scripts like scripts/run-extract.sh and scripts/run-mcp.sh to execute the scrapling Python package's CLI functions.
- [EXTERNAL_DOWNLOADS]: The scripts/install.sh script installs the scrapling library from PyPI and uses npx skills add to register the skill from the author's repository.
- [PROMPT_INJECTION]: The skill handles untrusted web data, presenting a surface for indirect prompt injection. Ingestion points: Fetcher classes (references/fetchers-and-sessions.md) and CLI commands (references/cli-and-mcp.md). Boundary markers: SKILL.md and references/research-harvesting.md recommend delimiters and user confirmation for scientific literature. Capability inventory: Subprocess calls in scripts/run-extract.sh and scripts/run-mcp.sh, plus network access via the WebFetch tool. Sanitization: The documentation encourages the use of CSS/XPath selectors and Markdown output to reduce the risk from raw HTML ingestion.
- [SAFE]: The scripts/research_harvest_gate.py script performs standard network requests to target domains to verify robots.txt compliance and identify paywalled publishers, which is a legitimate and ethical scraping feature.
Audit Metadata