vector
Audited by Socket on Aug 13, 2026
2 alerts found:
MalwareAnomalyThe provided fragment is strongly indicative of automation and anti-bot evasion: it outlines proxy-based routing, fingerprint/stealth manipulation (e.g., StealthPlugin, webdriver disabling, geo/locale/timezone consistency), operational bypass against Cloudflare/Akamai/PerimeterX/DataDome, and workflows involving CAPTCHA/bypass services to obtain clearance cookies/tokens. Even without direct system-compromise code, this is a high-risk, malicious-intent pattern consistent with bypassing access controls/anti-abuse mechanisms and enabling unauthorized scraping or account/session abuse. The fragment is truncated and may be documentation rather than directly executable code, so treat this as a high-risk indicator pending review of the full repository/package contents.
SUSPICIOUS: the core browser-automation capabilities fit the stated purpose and the main toolchain is official and verifiable, but the skill has a broad operational footprint: authenticated browsing, submission/upload actions, persistent session state, rich evidence capture, and multi-agent data routing. The strongest concern is the built-in stealth/anti-detection recipe with proxy rotation and fingerprint-matching guidance, which is disproportionate for many legitimate task-automation scenarios and raises the abuse risk even though the skill includes some safety boundaries.