ecommerce-promotion-deal-scraper

Warn

Audited by Socket on Jul 20, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The stated purpose matches ecommerce scraping, but the skill's footprint is enlarged by automatic installation of a separate Skill and external CLI without user confirmation. BrowserAct appears to be a legitimate same-org dependency from official docs/PyPI, so this is not confirmed malware, but the transitive trust chain, autonomous install behavior, and browser-based processing of untrusted pages make it a medium-high security risk.

Confidence: 86%Severity: 72%
Audit Metadata
Analyzed At
Jul 20, 2026, 04:36 AM
Package URL
pkg:socket/skills-sh/sam6dvpte34%2Fecommerce-skill%2Fecommerce-promotion-deal-scraper%2F@72ebb01badbfe2f27310cd8d6286e47fb289188188f19cf7e482c2ade8ecb237
Security Audit — socket — ecommerce-promotion-deal-scraper