scrapeninja

Warn

Audited by Socket on Sep 23, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's purpose broadly matches its behavior, but it requires users to trust Membrane as a full intermediary for authentication and API traffic rather than using ScrapeNinja's direct documented API pattern. The npm install source is legitimate, so this is not confirmed malware, but the third-party credential/data routing and mutable global CLI install raise medium risk.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
Sep 23, 2026, 03:04 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fscrapeninja%2F@b09eca0947718fff8e69340efd1d3eee19f6f495615fa9afa39c882908438e3a
Security Audit — socket — scrapeninja