web-article-extractor

Warn

Audited by Socket on Apr 12, 2026

1 alert found:

Anomaly
AnomalyLOW
references/platform-specific.md

This module is primarily a browser-side scraper/automation component that extracts article/post fields by injecting JavaScript into a target tab. It also includes explicit anti-bot evasion (user-agent spoofing and webdriver tampering), plus automated scrolling and modal/popup dismissal to reach and parse dynamic content. No direct evidence of OS-level compromise, credential theft, or outbound exfiltration is present in this fragment; however, the evasion behavior and use of javascript_exec make it suspicious from a security/compliance standpoint and warrant review of javascript_tool’s implementation and of how/where the extracted JSON is subsequently handled.

Confidence: 62%Severity: 56%
Audit Metadata
Analyzed At
Apr 12, 2026, 06:56 AM
Package URL
pkg:socket/skills-sh/dongbeixiaohuo%2Fwriting-agent%2Fweb-article-extractor%2F@a31a33e8df005ccd6c6763ace0a0896f6b665e34