Back to skill

Security audit

Scrapeless Pro Skill

Security checks for vulnerabilities and agentic risk

Overview

This scraper largely does what it advertises, but it needs review because it can browse arbitrary targets with weakened browser protections and can expose its license key in output.

Install only if you are comfortable running a commercial stealth-scraping browser tool in an isolated environment. Do not use it on sites or data you are not authorized to scrape, avoid authenticated or internal URLs, treat the license key as a secret, and prefer a sandboxed container or VM with restricted outbound network access.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scraper.js:219
Finding

Unrestricted URL Navigation Enables Server-Side Request Forgery

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scraper.js:71
Finding

TLS Verification and Chromium Sandbox Protections Are Disabled

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scraper.js:308
Finding

License Credential Is Disclosed in Plaintext Output

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (11)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The documented purpose emphasizes scraping, but the skill also includes license validation/gating and filesystem output behaviors that are not clearly declared as operational capabilities. This mismatch reduces transparency for users and agent frameworks, making it easier to hide consequential behaviors or obtain consent under incomplete disclosure.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill declares an environment-variable dependency but does not define an explicit tool scope or permissions boundary. In agent environments, missing scope declarations can cause users or orchestrators to grant broader access than intended, especially when the skill also performs browser automation and local file output.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill promotes stealth scraping and anti-bot bypass without warning users about privacy, legal, terms-of-service, or system-integrity implications. Because the context is specifically anti-detection web automation, omission of safety warnings makes misuse more likely and increases the risk of abusive or non-compliant deployment.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
84% confidence
Finding

Using 'npx playwright' without a pinned version allows execution of whatever package version resolves at install time, creating a supply-chain risk. A compromised or breaking upstream release could introduce malicious code or unsafe behavior into the skill setup path.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The activation prompt is broad and lacks boundaries on when the agent should invoke scraping behavior, which can lead to unintended autonomous use on arbitrary URLs or sensitive targets. In an agent setting, underspecified triggers increase the chance of overreach, privacy issues, or actions that violate site policies.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest describes a web-scraping capability, but the code additionally depends on reading a local secret from process.env for license enforcement. Accessing environment-held credentials is not an obvious requirement of scraping itself and expands the skill's access to host-side sensitive data.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The browser context is hard-coded to use en-US, America/New_York, and a fixed New York geolocation. This imposes a specific language/locale profile on all users without offering choice or documenting a justified regional constraint.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The validate command prints the full license key to the console, which exposes sensitive secret material to terminal history, logs, screenshots, CI output, and shell session recording tools. Although the secret is a product license rather than a cloud credential, it is still a reusable token that can be copied and abused by others.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

Printing the license key without warning creates an avoidable secret disclosure path and increases the chance that users leak credentials unintentionally into logs or support transcripts. The skill context does not require displaying the secret for scraping functionality, so this exposure is unjustified.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

The dependency is version-ranged with a caret, so future installs may pull newer minor/patch releases that were not specifically reviewed or tested. This creates supply-chain risk because a compromised or breaking upstream release could be introduced into the skill without any code change in this repository.

Content

Scanner excerpt · package.json (reported line 24)May include surrounding context.

json
],
  "license": "Commercial",
  "dependencies": {
    "playwright": "^1.58.0",
    "commander": "^12.0.0"
  }
}

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

The dependency is not strictly pinned and allows npm to resolve to later compatible releases at install time. In a scraping tool that depends on browser automation and CLI parsing, this increases supply-chain exposure and reproducibility risk if an upstream package is compromised or unexpectedly changes behavior.

Content

Scanner excerpt · package.json (reported line 25)May include surrounding context.

json
"license": "Commercial",
  "dependencies": {
    "playwright": "^1.58.0",
    "commander": "^12.0.0"
  }
}

Static analysis

No suspicious patterns detected.