ecommerce-product-image-reference-scraper

Warn

Audited by Socket on Jul 20, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core scraping purpose is coherent, and the BrowserAct CLI appears to use a plausibly official same-org distribution path, so this is not confirmed malware. Risk comes from automatic dependency installation without confirmation, transitive installation of another skill, and delegated live browser behavior that broadens the skill’s effective footprint beyond simple image-reference extraction.

Confidence: 86%Severity: 66%
Audit Metadata
Analyzed At
Jul 20, 2026, 04:19 AM
Package URL
pkg:socket/skills-sh/sam6dvpte34%2Fecommerce-skill%2Fecommerce-product-image-reference-scraper%2F@666006bd6fa13922bae20bf9e7a802ad24d8b885e54116490c398340872bcbb7
Security Audit — socket — ecommerce-product-image-reference-scraper