amazon-review-scraper

Warn

Audited by Socket on Sep 21, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/local_json_receiver.py

The code appears to be a straightforward local JSON collection utility, not malware. Its primary risks are unauthenticated arbitrary file creation or overwrite within the configured output directory, possible symlink-based escape, unrestricted request size, path disclosure, and accidental network exposure when --host is changed from localhost. Restrict binding to localhost, authenticate requests, enforce size limits, and use safer file creation that rejects symlinks if exposed to untrusted clients.

Confidence: 97%Severity: 67%
Audit Metadata
Analyzed At
Sep 21, 2026, 10:44 AM
Package URL
pkg:socket/skills-sh/pdben-auto%2Famazon-review-intelligence-skill%2Famazon-review-scraper%2F@85aa8793554b66eaf53edc0ec5e0a7a2c604e82d
Security Audit — socket — amazon-review-scraper