Back to skill

Security audit

Web Scraper

Security checks for vulnerabilities and agentic risk

Overview

This is a straightforward web-scraping instruction skill with expected network and optional file-output behavior, but users should keep scraping scope and output paths controlled.

Install only if you intend to use an agent for web scraping. Keep crawls limited to authorized targets, set small page limits, respect robots.txt and rate limits, and verify any --output path before writing scraped data locally.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill performs network scraping and crawling, including JavaScript-rendered pages and multi-page crawling, but does not provide privacy, authorization, or integrity warnings. In an agent environment, this can cause collection of sensitive data from authenticated sessions, interaction with untrusted sites, or crawling beyond user intent, increasing risk of data exposure and unintended network activity.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill explicitly demonstrates writing scraped data to a local file via --output ./products.json but does not warn users that running the skill can create or overwrite local files. In an agent setting, omission of this behavior can surprise users, lead to unintended persistence of scraped content, or overwrite data if output paths are changed or templated.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.