web-scraping

Warn

Audited by Socket on Mar 18, 2026

3 alerts found:

SecurityAnomalyx2
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated web-scraping purpose matches much of the behavior, but the skill’s footprint is unusually aggressive for an AI agent because it relies on traffic interception, stealth/anti-detection, and token/header capture. Official Apify pieces are coherent, yet the unverified Proxy-MCP dependency and offensive scraping workflow make the overall skill high risk rather than benign.

Confidence: 81%Severity: 72%
AnomalyLOW
strategies/dom-scraping.md

The file is a straightforward operational guide for DOM scraping using a DevTools bridge and an anti-detection humanizer. It contains explicit instructions to extract cookies and storage tokens and to reuse them in HTTP requests (gotScraping), plus strong advice to operate stealthily. This makes it a high-risk guide for credential harvesting and undetected scraping when used maliciously. There is no obfuscated or self-executing malware in the text, but the instructions materially enable unauthorized access and data exfiltration if applied without consent. Treat this material as dual-use: acceptable for authorized testing but potentially dangerous if used for abuse.

Confidence: 85%Severity: 60%
AnomalyLOW
reference/fingerprint-patterns.md

This document is non-executable documentation that describes and encourages techniques to evade bot detection: browser fingerprint spoofing, TLS/J A3 spoofing, proxy chaining, humanizer emulation, and aggressive session rotation. There is no direct code performing I/O or exfiltration in this fragment, so it is not malware by itself. However, it provides clear operational guidance that can facilitate abusive scraping, account takeover, or other automated evasion. Treat inclusion of these instructions in a package as a moderate-to-high abuse risk and review the broader package for executable code that implements these techniques.

Confidence: 90%Severity: 60%
Audit Metadata
Analyzed At
Mar 18, 2026, 06:26 PM
Package URL
pkg:socket/skills-sh/yfe404%2Fweb-scraper%2Fweb-scraping%2F@40ef9f8c45d48e7d58087da4dfeb6394c9533495