ai-web-scraping-scrapegraph

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's scraping purpose is plausible, but its actual data flow sends all requests and optional site credentials through Gooseworks proxy infrastructure instead of ScrapeGraph's official API, while also reading raw local credentials from disk. Same-org CLI guidance reduces installer concerns, but the proxy-based credential and data routing make the skill materially riskier than its description suggests.

Confidence: 89%Severity: 81%
Audit Metadata
Analyzed At
Apr 28, 2026, 01:07 PM
Package URL
pkg:socket/skills-sh/gooseworks-ai%2Fgoose-skills%2Fai-web-scraping-scrapegraph%2F@131d0cbd970881c46970c653492d8e8cab40908b