site-data-collector

Warn

Audited by Socket on Jul 24, 2026

2 alerts found:

Securityx2
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's scraping behavior mostly matches its stated purpose, and the disclosed data flow appears same-org/local rather than an obvious credential-harvesting proxy. However, the trust-critical Frevana desktop/CLI is installed through an unpinned remote 'latest' setup script and is not publicly verifiable from the provided evidence; it then receives authenticated browser-session capability. That combination makes the skill high risk despite not being confirmed malware.

Confidence: 84%Severity: 82%
SecurityMEDIUM
scripts/setup.sh

This module is not obviously malicious by itself, but it is a high-risk supply-chain wrapper: it downloads a shell script from a mutable remote branch URL and executes it immediately without integrity/authenticity controls. This pattern materially increases the likelihood of successful upstream/URL compromise leading to arbitrary code execution on consumers.

Confidence: 78%Severity: 85%
Audit Metadata
Analyzed At
Jul 24, 2026, 01:32 AM
Package URL
pkg:socket/skills-sh/FinpeakInc%2Ffrevana-skills%2Fsite-data-collector%2F@58970687381e498000b9f3f1e670574ded0fb32caa6d38c32dc04741e935538e
Security Audit — socket — site-data-collector