go-rod-master
Audited by Socket on Jun 26, 2026
2 alerts found:
Anomalyx2SUSPICIOUS: the skill is mostly coherent as a go-rod automation guide, but it goes beyond ordinary scraping documentation by centering stealth anti-bot evasion, request hijacking, and TLS-ignore patterns. Install sources are mostly legitimate official Go modules, yet the unpinned @latest usage and personal-account launcher path reduce trust. No clear credential harvesting or attacker-controlled exfiltration is present, so this is not confirmed malware, but it is a medium-risk skill with notable abuse potential.
The code is an automation tool that demonstrates stealth browser techniques to bypass bot detection and test detection sites. It does not read sensitive inputs, nor does it appear to exfiltrate data or execute backdoors. The primary security considerations are potential misuse for evading anti-bot defenses and resource usage (browser download and headless browsing). Overall risk is moderate due to evasion usage but no malicious payload is evident in the fragment.