Web Scrape Plus

Security checks across malware telemetry and agentic risk

Overview

This scraping skill is openly about web extraction, but it includes anti-detection, proxy, stealth, CAPTCHA, and login-cookie guidance without enough limits around authorization or session safety.

Install only if you intend to use it for authorized, compliant scraping. Do not use it to bypass access controls, terms of service, anti-bot protections, or scrape private/login-gated data without permission. Treat cookies, account sessions, logs, caches, and scraped data as sensitive, and prefer official APIs or transparent rate-limited collection where available.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill explicitly supports scraping login-gated sites with session management and cookies, but provides no warning about handling authenticated data, consent, session security, or site authorization boundaries. In a scraping-focused skill, this increases the risk that users will collect protected account data or misuse active sessions without adequate safeguards.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill prominently advertises anti-detection features such as user-agent rotation, fingerprint evasion, proxy routing, and stealth techniques without clear restrictions or abuse warnings. These capabilities are not inherently malicious, but in this context they materially enable bypass of third-party anti-bot controls and make unauthorized or deceptive scraping more practical.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal