scrapling
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [DATA_EXFILTRATION]: The wrapper script
scrapling_fetch.pyexplicitly disables SSL certificate verification by settingverify=Falsein thefetch_httpfunction call toFetcher.get. While intended to address certificate compatibility issues on certain systems, this practice significantly increases the risk of man-in-the-middle (MITM) attacks during network operations. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to fetch and process arbitrary content from the web, which creates a surface for indirect prompt injection attacks.
- Ingestion points: The
scrapling_fetch.pyscript and theFetcherAPI classes inSKILL.mdretrieve content from external, untrusted URLs provided as input. - Boundary markers: The skill does not implement delimiters or specific instructions to the agent to ignore or isolate potentially malicious instructions embedded in the scraped data.
- Capability inventory: The skill possesses network access capabilities and returns external data to the agent context. It does not contain functions for arbitrary file writing or shell command execution based on the scraped content.
- Sanitization: There is no evidence of HTML sanitization, script filtering, or instruction escaping performed on the fetched content before it is passed to the agent.
- [EXTERNAL_DOWNLOADS]: The script
scrapling_install.shperforms an unversioned installation of thescrapling[all]package from the Python Package Index (PyPI). It also executesscrapling install, which triggers the download of Chromium and other browser binaries required for dynamic rendering and stealth fetching. - [COMMAND_EXECUTION]: The skill requires the execution of a setup script
scrapling_install.shthat modifies the system environment by installing Python packages and browser dependencies.
Audit Metadata