Back to skill

Security audit

Nmb Scrapling

Security checks across malware telemetry and agentic risk

Overview

This is a legitimate scraping helper, but it exposes anti-bot bypass, session reuse, proxy rotation, and large-crawl workflows without enough authorization and scoping guardrails.

Review before installing. Use this only for websites you are authorized to scrape, and treat stealth mode, Cloudflare solving, proxy rotation, logged-in sessions, large crawls, and MCP access as explicit opt-in features. Pin and verify the Scrapling package where practical, set scope and rate limits, respect robots.txt and site terms, minimize sensitive data collection, and clean up crawl/session state when done.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger list is broad and includes generic phrases like 'extract data from' and common Chinese scraping requests, which can cause the skill to activate for ordinary informational queries rather than clearly authorized scraping tasks. In this skill's context, that is more dangerous because the capability explicitly includes anti-bot and Cloudflare bypass, so accidental routing can expose users to compliance, privacy, and abuse risks.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The skill prominently advertises anti-bot bypass, Cloudflare solving, session reuse, proxy rotation, and large-scale crawling, but provides no clear warning about authorization, terms-of-service, privacy, or lawful data handling. This omission is especially risky in context because the skill is not just a neutral parser; it encourages use cases that can facilitate unauthorized scraping and collection of personal or restricted data.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.