browser-automation

Warn

Audited by Socket on Sep 22, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/scraping_toolkit.py

The fragment does not show clear malware, credential theft, persistence, destructive behavior, or covert data exfiltration. It is a web-scraping code generator with dual-use User-Agent rotation and a stealth rate profile. Security concerns include unsafely embedding --url into generated Python source, unrestricted requests to caller-selected hosts that can reach internal services, arbitrary output-path writing as an explicit feature, and a runtime bug in JSON output handling. The code should escape or safely serialize generated constants, restrict targets to approved HTTP(S) hosts where appropriate, and fix json.dumps usage.

Confidence: 98%Severity: 58%
Audit Metadata
Analyzed At
Sep 22, 2026, 06:23 PM
Package URL
pkg:socket/skills-sh/borghei%2Fclaude-skills%2Fbrowser-automation%2F@a5911fef075fafaa883a488d4749dbb77115b0853280482f4ff41ef11fde7c0c
Security Audit — socket — browser-automation