scrapedo-web-scraper
Fail
Audited by Socket on Feb 16, 2026
1 alert found:
Obfuscated FileObfuscated FileSKILL.md
HIGHObfuscated FileHIGH
SKILL.md
The package implements an expected capability (proxying fetches through Scrape.do) and contains no obvious malicious code in the provided fragment. However, it introduces significant privacy and supply‑chain risk because it can forward arbitrary page contents — including potentially sensitive, authenticated, or PII-bearing pages — to a third‑party service without visible safeguards. Treat this as a security/privacy risk: acceptable for targeted, informed use with trusted service and strong controls, but dangerous if used automatically in production or on internal URLs without restrictions.
Confidence: 98%
Audit Metadata