scraping-specialist

Warn

Audited by Socket on Jun 24, 2026

4 alerts found:

Securityx2Anomalyx2
SecurityMEDIUM
references/domains/ida-pro-skills/ida-domain-scripting/SKILL.md
AnomalyLOW
references/domains/review-intelligence/scripts/tpscraper.js

No explicit malicious payload behavior (e.g., credential theft, reverse shells, direct exfiltration, dynamic code execution) is visible in the provided fragment. However, the module is clearly designed for automated scraping and intentionally weakens browser security boundaries (no-sandbox/disable-web-security/site isolation disabling) and uses stealth/bot-evasion. Additionally, it accepts arbitrary proxy configuration from CLI and routes all browsing through it. Given the snippet truncation, the highest-impact aspects—how scraped data is handled/saved and whether any additional network exfiltration occurs—cannot be verified from this fragment alone. Overall: likely an automation/scraper with meaningful security hardening concerns rather than evident malware.

Confidence: 60%Severity: 62%
AnomalyLOW
SKILL.md

SUSPICIOUS. The top-level router is mostly consistent with scraping workflows, but the inclusion of IDA Pro reverse-engineering/plugin-development sub-skills is a significant purpose mismatch that broadens the agent's capability beyond web scraping. No direct malware, credential theft, or installer abuse appears in this file, but the skill composition is internally inconsistent and raises medium security concern.

Confidence: 88%Severity: 57%
SecurityMEDIUM
references/domains/ida-pro-skills/ida-domain-expert/SKILL.md
Audit Metadata
Analyzed At
Jun 24, 2026, 06:23 PM
Package URL
pkg:socket/skills-sh/Prorise-cool%2Fprorise-claude-skills%2Fscraping-specialist%2F@b77c9c84b380873a157963385b53db90941ce5bf
Security Audit — socket — scraping-specialist