ecommerce-promotion-deal-scraper
Warn
Audited by Socket on Jul 20, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: The stated purpose matches ecommerce scraping, but the skill's footprint is enlarged by automatic installation of a separate Skill and external CLI without user confirmation. BrowserAct appears to be a legitimate same-org dependency from official docs/PyPI, so this is not confirmed malware, but the transitive trust chain, autonomous install behavior, and browser-based processing of untrusted pages make it a medium-high security risk.
Confidence: 86%Severity: 72%
Audit Metadata