executing-web-scraping

Warn

Audited by Socket on Jul 28, 2026

2 alerts found:

Securityx2
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s core purpose is coherent with scraping, but its footprint materially expands into anti-bot evasion, mobile API interception, and routing through third-party scraping services. It is not confirmed malware, yet it equips an AI agent with high-risk offensive collection techniques and nontrivial credential/data-flow exposure.

Confidence: 84%Severity: 74%
SecurityMEDIUM
references/evasion.md

This fragment is high-risk supply-chain-adjacent content because it provides actionable instructions and code to evade anti-bot/WAF defenses (including TLS fingerprint spoofing and stealth automation) and to bypass mobile SSL pinning using Frida/mitmproxy to intercept and replicate API traffic. While it does not show classic malware payload mechanics, it meaningfully enables circumvention and potential unauthorized data collection. Treat as dangerous content and investigate whether it is merely documentation or is executed by the package.

Confidence: 70%Severity: 90%
Audit Metadata
Analyzed At
Jul 28, 2026, 09:18 AM
Package URL
pkg:socket/skills-sh/lucasvibecoder%2Fgtme-skills%2Fexecuting-web-scraping%2F@d3526c3a4ada73e2d6c3b9e04b18aa5fcc01fa78f629a88e1b0f342575c9d446
Security Audit — socket — executing-web-scraping