T08 · Insecure Dependencies
- Location
SKILL.md:12- Finding
Unpinned Third-Party Package Installed Globally
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a document scraper with coherent goals, but it asks users to install an unverified global CLI and handles credentials, persisted sessions, local document deletion, and external Claude page analysis with insufficient scoping and warnings.
Install only if you trust the docs-scraper npm package and its publisher. Avoid entering real passwords in command-line arguments, clear saved profiles when finished, treat PDFs under ~/.docs-scraper/output as sensitive, and avoid the LLM fallback for private or authenticated pages unless you are comfortable sending page HTML to Claude.
SKILL.md:12Unpinned Third-Party Package Installed Globally
SKILL.md:54Passwords Exposed Through Command-Line Arguments
The documentation describes profile-based authenticated scraping but does not clearly warn that session cookies are persisted and that downloaded files are stored locally, which can expose sensitive documents or reusable authentication state to other local users, backups, or endpoint compromise. This is especially important in a scraping tool handling protected Notion and DocSend content.
The documentation states that the daemon automatically cleans up files older than 1 hour and that docs-scraper cleanup deletes all PDFs, but it does not warn users that these are destructive operations. Since deletion is irreversible from the user's perspective, the skill description should clearly disclose this behavior.
The documented LLM fallback materially expands the skill's behavior from document-to-PDF conversion into arbitrary webpage analysis with external transmission of page content to Claude. Because it also detects login forms and dynamic credential fields, users could unknowingly send sensitive page HTML and authentication context to a third party, which creates privacy, credential-handling, and scope-creep risk beyond the stated purpose.
Requiring an ANTHROPIC_API_KEY for page analysis indicates outbound sharing of webpage data with an external service that is not clearly necessary for a scraper whose advertised purpose is local PDF generation. This mismatch can mislead operators about data flows and increases the chance that sensitive internal documents, login pages, or metadata are processed by a third party without clear consent.
No suspicious patterns detected.