Caveat verdict

scrapling-official

88
🟢 Trusted
No high-risk patterns surfaced by the deep scan — automated capability review, not behavioral proof.

Official Scrapling library skill by the library author, covering CLI and Python API for web scraping; executionSinkDetected is a weak hint here as all code examples are documented scraping commands, with no exfiltration or malicious pattern evident.

⚠ Flagged for review — coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.

Automated static analysis — not a human review. Caveat flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.

0
security
100
transparency
90
maintenance

Findings (8)

Pattern match critical

<script> tag in markdown — potential code injection

references/parsing/main_classes.md · code · <script

Pattern match high

Pipe to python — executes piped content as Python code

examples/README.md · prose · downgraded · | Python

Pattern match high

Instructs covert action — may act without user awareness

references/spiders/getting-started.md · code · silently

Pattern match medium

Opens WebSocket connection

references/fetching/dynamic.md · code · websocket

Pattern match medium

POSTs data to external URL

references/fetching/static.md · code · .post('https://

Pattern match medium

Popular HTTP library — network access

references/spiders/advanced.md · code · Got

Pattern match low

Makes HTTP request to external URL

references/fetching/choosing.md · code · fetch('https://

Pattern match low

Base64 encoding/decoding

references/spiders/advanced.md · prose · downgraded · base64-encode

Why the tier is capped

Execution sink present in raw bytes (Hard Floor: class B). Final tier capped at Caution — cannot be lifted by any downgrade, example-payload opt-in, or allowlist.

Permissions & capabilities

Requires 1 system binary.

network_in

Is this flag fair?

Check another skill Browse the registry Auditing your own skills or configs? Use the API