ultimate-scraper

Warn

Audited by Socket on Jun 1, 2026

2 alerts found:

Securityx2
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally coherent for a stealth web-scraping purpose, but that purpose itself requires high-risk evasive capabilities, broad external credential use, third-party solver/LLM data flows, and post-install browser binary downloads. The strongest concerns are anti-bot bypass functionality, credential forwarding to unrelated services, and indirect prompt-injection exposure from scraping untrusted web content with Python-capable tooling.

Confidence: 89%Severity: 78%
SecurityMEDIUM
README.md

No executable code is shown—only a feature/architecture description. The documented functionality strongly indicates an automation framework intended to bypass anti-bot protections (stealth/anti-detect, TLS spoofing, fingerprint persistence) and to solve CAPTCHAs via third parties, followed by AI/LLM-based extraction that may transmit scraped content to external providers. This is a meaningful abuse/policy-evasion risk even though there is no direct evidence of malware in the provided fragment. A definitive supply-chain/malware assessment requires reviewing the actual source files for network destinations, credential handling, logging/telemetry, and any hidden install-time or runtime behavior.

Confidence: 44%Severity: 70%
Audit Metadata
Analyzed At
Jun 1, 2026, 06:17 AM
Package URL
pkg:socket/skills-sh/yoloshii%2Fultimate-scraper-skill%2Fultimate-scraper%2F@1a1efab0c2b5f20d78e1405f3445b1880a82fa99
Security Audit — socket — ultimate-scraper