crawl-cli
Warn
Audited by Socket on Feb 25, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
The code fragment represents a well-scoped, ethically oriented web crawling framework with proper rate limiting, error handling, and robots.txt awareness. It shows no signs of credential leakage or malware, and its security risk is primarily related to potential overuse or misconfiguration in production (log exposure, policy violations). Recommended improvements include explicit logging sanitization, configurable log destinations, optional user-provided robots policy enforcement, and stricter enforcement of Terms of Service during runtime. Overall, it remains low-risk for supply-chain security when used as intended with trusted dependencies.
Confidence: 75%Severity: 75%
Audit Metadata