scraper-studio
Warn
Audited by Socket on Sep 16, 2026
1 alert found:
AnomalyAnomalyreferences/recipes.md
LOWAnomalyLOW
references/recipes.md
This is documentation for a scraper self-healing workflow, not apparent malware. It contains a significant command-injection risk because it recommends executing JSON-derived content with eval. The risk depends on whether approve.json and its next_step field are fully trusted and strictly generated; that cannot be verified from the shown fragment. The optional auto-approval mode reduces human oversight but is not itself evidence of malicious intent.
Confidence: 96%Severity: 67%
Audit Metadata