Back to skill

Security audit

Scrapeless Webunlocker Skill

Security checks for vulnerabilities and agentic risk

Overview

This skill openly uses a third-party scraping service to bypass website protections, but its broad anti-bot bypass capability and limited data-safety warnings require review before installation.

Review this skill carefully before installing. Use it only for sites and data you are authorized to access, and do not pass cookies, Authorization headers, private endpoints, regulated data, or credential-bearing proxy URLs unless you have approved sending them to Scrapeless. Install in an isolated environment and pin or audit dependencies before use.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
requirements.txt:1
Finding

Unpinned Python Dependencies Create a Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Location: requirements.txt:1-2
Vulnerability Type: Unconstrained third-party dependencies
Risk Level: Medium

Vulnerable Code

text
requests
python-dotenv

The documented installation workflow in README.md:116-121 installs these unconstrained dependencies:

bash
cd webunlocker-skill
pip install -r requirements.txt

Technical Analysis

Both runtime dependencies are specified without exact versions or package hashes. Consequently, installation resolves whichever compatible releases are available from the user's configured Python package index at that time. The project therefore lacks a reproducible, integrity-verified dependency set.

If a dependency release, package-maintainer account, package-index account, or configured package mirror is compromised, a malicious release could be selected during installation. Package installation hooks or malicious runtime code could then execute with the privileges of the user installing or invoking the Skill.

This is especially relevant because the process handles the X_API_TOKEN environment credential and user-provided scraping inputs. The finding does not establish that the current requests or python-dotenv packages are malicious; it identifies the absence of controls preventing future dependency substitution or compromise.

Attack Path

  1. An attacker compromises a dependency publisher, distribution account, or package mirror used by the victim.
  2. The attacker publishes a malicious release under the legitimate dependency name.
  3. A user follows the documented pip install -r requirements.txt installation procedure.
  4. Because no version or hash is enforced, pip may resolve and install the attacker-controlled release.
  5. Malicious installation or runtime code executes under the installing user's account.
  6. The payload may read accessible environment variables, including X_API_TOKEN, inspect ...[truncated 799 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin each dependency to a reviewed, exact version rather than allowing unconstrained resolution.

  2. Generate and commit a lock file containing all transitive dependencies.

  3. Record cryptographic hashes and require verification during installation, for example:

    bash
    pip install --require-hashes -r requirements.txt
    
  4. Generate hashes from a trusted, controlled environment and review dependency updates before modifying the lock file.

  5. Use automated dependency vulnerability and provenance scanning in CI.

  6. Install dependencies in an isolated virtual environment under a non-privileged account.

  7. Avoid exposing X_API_TOKEN or other credentials during dependency installation.

  8. Configure trusted package indexes explicitly and avoid unverified third-party mirrors.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (15)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 131)May include surrounding context.

  1. Create a .env file in the root directory based on the .env.example file:
bash
cp .env.example .env
  1. Add your Scrapeless API token to the .env file:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/webunlocker.py (reported line 25)May include surrounding context.

python
)
logger = logging.getLogger(__name__)

# Load environment variables from .env file
load_dotenv()

try:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/webunlocker.py (reported line 45)May include surrounding context.

python
)
logger = logging.getLogger(__name__)

# Load environment variables from .env file
load_dotenv()

try:

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README explicitly markets a tool for accessing sites that block automated traffic and extracting data while omitting any warning about authorization, terms-of-service, privacy, or legal constraints. In a scraping skill, that omission increases the likelihood of misuse because the documentation frames anti-bot evasion as a standard capability rather than a controlled, compliant activity.

Content

No source excerpt is available for this finding.

Ssd 2

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This section promotes bypassing bot protections such as Cloudflare, CAPTCHA, IP blocking, and JavaScript defenses to retrieve data from 'difficult targets.' In context, that is dangerous because the core feature set is framed around defeating access controls, which can facilitate unauthorized scraping and evasion of protective mechanisms.

Content

No source excerpt is available for this finding.

Ssd 2

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The feature and use-case language normalizes challenge-solving and stealth scraping as ordinary automation features without acknowledging the security function of those mechanisms. That makes the skill more dangerous in context because it encourages operational use against protected sites rather than narrowly scoped, authorized scraping scenarios.

Content

No source excerpt is available for this finding.

Ssd 2

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The example command explicitly demonstrates bypassing a Cloudflare Turnstile challenge, which is a concrete anti-bot circumvention workflow rather than a neutral capability description. Providing a ready-to-run example materially lowers the barrier to misuse and directly operationalizes evasion of a third-party protection mechanism.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill exposes environment and network capabilities but does not declare any explicit tool scope or permissions metadata. This weakens transparency and policy enforcement, making it easier for an agent or user to invoke networked behavior with access to secrets like X_API_TOKEN without clear boundaries or review.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill encourages sending URLs, headers, POST bodies, and potentially captured network traffic to Scrapeless, a third-party scraping provider, but does not clearly warn users that sensitive request data may leave the local environment. In this context, users may unknowingly transmit session cookies, authorization headers, form data, or internal URLs to an external service, creating meaningful confidentiality and compliance risk.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

This code transmits collected request parameters to an external API endpoint, which creates an external data disclosure boundary. Because the skill is specifically designed to bypass website blocks via a third-party service, the context makes the transmission more sensitive: arbitrary user inputs and potentially sensitive request metadata leave the local trust boundary and are processed by an outside provider.

Content

Scanner excerpt · scripts/webunlocker.py (reported line 143)May include surrounding context.

python
js_render=js_render
            )
            
            response = requests.post(
                f"{self.api_base_url}{self.endpoint}",
                headers=self.headers,
                json=payload,

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The tool forwards user-supplied URLs, headers, request bodies, and rendering instructions to a third-party service without any explicit disclosure or guardrails. In a skill context, users may assume the request is made directly from the local environment, so sensitive URLs, cookies, authorization headers, or posted data could be unintentionally exfiltrated to the external scraping provider.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
98% confidence
Finding

The dependency requests is declared without a version pin, which makes builds non-reproducible and can unexpectedly pull in vulnerable or breaking releases over time. In a scraping skill that performs outbound web requests, dependency drift increases supply-chain and reliability risk, though this file alone does not prove exploitation.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
requests
python-dotenv

Unverifiable Dependency: requests has 16 known advisory(ies) (CVE-2014-1830 (Exposure of Sensitive Information to an Unauthorized Actor in Requests); CVE-2024-47081 (Requests vulnerable to .netrc credentials leak via malicious URLs); CVE-2024-35195 (Requests `Session` object does not verify requests after making first request wi) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
91% confidence
Finding

requests has known advisories, and because no version is pinned, there is no way to verify from this manifest whether the installed package is patched. In a web-scraping skill that makes arbitrary outbound requests, any vulnerable requests version is more relevant because hostile endpoints and URLs are part of the expected threat surface.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
98% confidence
Finding

The dependency python-dotenv is also unpinned, so installations may resolve to different versions in different environments, including versions with security defects. Because dotenv libraries often touch local configuration and secrets, version ambiguity can increase the chance of introducing vulnerable behavior.

Content

Scanner excerpt · requirements.txt (reported line 2)May include surrounding context.

text
requests
python-dotenv

Unverifiable Dependency: python-dotenv has 2 known advisory(ies) (CVE-2026-28684 (python-dotenv: Symlink following in set_key allows arbitrary file overwrite via ); CVE-2026-28684 (python-dotenv reads key-value pairs from a .env file and can set them as environ)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
87% confidence
Finding

python-dotenv has known advisories, and the unpinned manifest prevents determining whether a safe version will actually be installed. While the risk depends on whether vulnerable dotenv functionality is used elsewhere, unresolved version selection leaves a plausible path to secret-handling or file-overwrite issues.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.