scrapin-io

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The skill is mostly coherent with its stated purpose, and the install path appears to use an official same-org npm package rather than a suspicious binary. The main risk is architectural: it routes authentication and API traffic through Membrane instead of directly to Scrapin.io, creating moderate credential-forwarding and intermediary data-flow risk. Overall this is better classified as suspicious-by-design rather than malicious.

Confidence: 86%Severity: 56%
Audit Metadata
Analyzed At
Apr 22, 2026, 09:51 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fscrapin-io%2F@4e2913d398fa2dfef44cf8e01bfef18b444d4d53