autocli-web-scraping
Warn
Audited by Socket on May 18, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The core scraping capability is coherent, and the installer appears to be the official upstream project, so this is not confirmed malware. However, the skill’s footprint is broader than its stated scraping purpose: it side-loads a browser extension, stores/sends tokens to a cloud service with overridable endpoint, and exposes autonomous social-media and recruiter actions with real-world consequences. Medium-to-high risk overall due to supply-chain hygiene, credential routing flexibility, and disproportionate action scope.
Confidence: 87%Severity: 74%
Audit Metadata