scraper-studio

Warn

Audited by Socket on Sep 16, 2026

1 alert found:

Anomaly
AnomalyLOW
references/recipes.md

This is documentation for a scraper self-healing workflow, not apparent malware. It contains a significant command-injection risk because it recommends executing JSON-derived content with eval. The risk depends on whether approve.json and its next_step field are fully trusted and strictly generated; that cannot be verified from the shown fragment. The optional auto-approval mode reduces human oversight but is not itself evidence of malicious intent.

Confidence: 96%Severity: 67%
Audit Metadata
Analyzed At
Sep 16, 2026, 12:46 PM
Package URL
pkg:socket/skills-sh/brightdata%2Fskills%2Fscraper-studio%2F@abfedb7cc57d670a8480aa9a647e7b9bda719b9d4ac805c7b1d6a17af2630b87
Security Audit — socket — scraper-studio