sephora-product-scraper

Warn

Audited by Socket on Jul 20, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the stated scraping purpose matches the browser-automation capability, and the named dependency appears to be an official BrowserAct runtime. The main risk is proportionality and trust expansion: this skill is mostly a wrapper that can auto-install and invoke another Skill/CLI without separate approval, creating transitive supply-chain and autonomous-install risk rather than clear malicious behavior.

Confidence: 85%Severity: 58%
Audit Metadata
Analyzed At
Jul 20, 2026, 04:20 AM
Package URL
pkg:socket/skills-sh/sam6dvpte34%2Fecommerce-skill%2Fsephora-product-scraper%2F@7f32054a5d0243c9b9e8bab6f18c1d914c2dc98a712e53f7d230528604ac42d4
Security Audit — socket — sephora-product-scraper