amazon-reviews-api-skill

Warn

Audited by Socket on Feb 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This skill is functionally coherent: it asks for a BrowserAct API key and an ASIN, runs a local Python script which calls a third-party Amazon review extraction API, and prints structured review data. The main security concerns are supply-chain/trust and privacy: reviewer PII and request metadata are sent to a third-party scraping provider (BrowserAct), the skill lacks documentation of endpoints, retention, and privacy policies, and it advises bypassing CAPTCHAs and IP restrictions which may contravene Amazon's terms. There is no evidence in the provided text of credential-harvesting, obfuscated payloads, or direct malicious code. Recommended mitigations: verify BrowserAct's trustworthiness and data handling policies before providing API keys, avoid collecting unnecessary PII, and ensure legal/TOS compliance for scraping.

Confidence: 80%Severity: 75%
Audit Metadata
Analyzed At
Feb 28, 2026, 08:01 AM
Package URL
pkg:socket/skills-sh/browser-act%2Fskills%2Famazon-reviews-api-skill%2F@17e377199e5eede6ffb7b48800721382f3f84398