review-site-scraper

Warn

Audited by Socket on Apr 10, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s purpose matches review scraping, and the required APIFY_API_TOKEN is proportionate. However, its real footprint relies on remote execution of third-party Apify actors, so data and credentials flow through hosted code not operated by the review platforms and not pinned as immutable artifacts. This is not confirmed malware, but it is a medium-risk credential-forwarding and remote supply-chain pattern.

Confidence: 86%Severity: 58%
Audit Metadata
Analyzed At
Apr 10, 2026, 10:49 AM
Package URL
pkg:socket/skills-sh/gooseworks-ai%2Fgoose-skills%2Freview-site-scraper%2F@0ce3b182670d2365cdbaaea9c74fe122b8975626