scrape-leads

Fail

Audited by Socket on Mar 6, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The codebase is an automation pipeline for scraping, classifying, enriching, and persisting business leads. I found no explicit malicious code or obfuscation techniques in the provided specification. The primary risks are: credential exposure (multiple API keys and Google service account), privacy/compliance (bulk scraping and enrichment with no consent or suppression), and operational abuse (high-volume parallel scraping without rate-limiting). Practical mitigations: restrict service-account scopes, store secrets in a proper secret manager, implement secure deletion of .tmp artifacts, add rate-limiting/backoff and polite scraping practices, and add privacy/compliance controls (consent, data retention policy, geo-restrictions). Overall, treat this as a high-privilege, high-privacy-risk tool that is not demonstrably malicious but requires careful operational controls.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 6, 2026, 02:20 PM
Package URL
pkg:socket/skills-sh/aiagentwithdhruv%2Fskills%2Fscrape-leads%2F@676a2e6deb7c7666a0958691c0928d73d3145a44