Back to skill

Security audit

Craigslist Monitor

Security checks across malware telemetry and agentic risk

Overview

This skill openly scrapes Craigslist listings for sales leads and can save them locally, with privacy and compliance considerations but no hidden or destructive behavior found.

Before installing, confirm you are comfortable scraping Craigslist and collecting public contact details for outreach. Review applicable site rules and outreach laws, protect or delete saved lead files when no longer needed, verify the local Scrapling dependency, and only add the weekly cron job if you want recurring scraping.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
86% confidence
Finding
The script collects and persists lead information including phone numbers, locations, and URLs into a local master file without any consent check, retention control, minimization, or privacy notice. In this skill context, the purpose is explicitly lead scraping for outreach, which makes the uncontrolled storage of scraped contact data more sensitive and raises compliance and privacy risk if the file is shared, synced, or reused improperly.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.