site-data-collector
Audited by Socket on Jul 24, 2026
2 alerts found:
Securityx2SUSPICIOUS. The skill's scraping behavior mostly matches its stated purpose, and the disclosed data flow appears same-org/local rather than an obvious credential-harvesting proxy. However, the trust-critical Frevana desktop/CLI is installed through an unpinned remote 'latest' setup script and is not publicly verifiable from the provided evidence; it then receives authenticated browser-session capability. That combination makes the skill high risk despite not being confirmed malware.
This module is not obviously malicious by itself, but it is a high-risk supply-chain wrapper: it downloads a shell script from a mutable remote branch URL and executes it immediately without integrity/authenticity controls. This pattern materially increases the likelihood of successful upstream/URL compromise leading to arbitrary code execution on consumers.