browser-automation
Warn
Audited by Socket on Sep 22, 2026
1 alert found:
AnomalyAnomalyscripts/scraping_toolkit.py
LOWAnomalyLOW
scripts/scraping_toolkit.py
The fragment does not show clear malware, credential theft, persistence, destructive behavior, or covert data exfiltration. It is a web-scraping code generator with dual-use User-Agent rotation and a stealth rate profile. Security concerns include unsafely embedding --url into generated Python source, unrestricted requests to caller-selected hosts that can reach internal services, arbitrary output-path writing as an explicit feature, and a runtime bug in JSON output handling. The code should escape or safely serialize generated constants, restrict targets to approved HTTP(S) hosts where appropriate, and fix json.dumps usage.
Confidence: 98%Severity: 58%
Audit Metadata