amazon

Warn

Audited by Socket on Mar 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

Functionally legitimate scraping tool for Amazon.com.br with features to improve reliability by reusing local authenticated cookies and using a stealth browser. Primary security concerns are: (1) cookie extraction and persistence (export/cache) — these are highly sensitive and can enable account impersonation if files or runtime are compromised; (2) supply-chain risk from camoufox/playwright runtime downloads and third-party dependencies. No explicit evidence of malware, obfuscated malicious code, or external exfiltration domains in the provided fragment. Recommend: restrict execution to trusted environments, avoid exporting cookies to shared locations, secure cache file permissions, verify integrity of third-party tools and downloads, and consider least-privilege alternatives (ask users to provide session cookies explicitly or use ephemeral auth tokens) where possible.

Confidence: 98%Severity: 75%
Audit Metadata
Analyzed At
Mar 1, 2026, 06:23 AM
Package URL
pkg:socket/skills-sh/quantmind-br%2Fskills%2Famazon%2F@7e3a3ba527c1a9e9af0013991d307064cd030344