扫描报告
5 /100
brave-loggedin-tag-browsing
使用 Brave 瀏覽器(已登入狀態)瀏覽 X/Twitter、Facebook 用戶頁面並提取最新帖子
This is a legitimate social media scraping tool using Playwright for browser automation to extract public posts from X/Twitter and Facebook. No malicious behavior, credential theft, or data exfiltration detected.
可以安装
This skill is safe to use. Minor improvements: fix hardcoded path in dist/index.js and correct the undefined export reference in execute.js.
安全发现 2 项
| 严重性 | 安全发现 | 位置 |
|---|---|---|
| 低危 | Minor path inconsistency 文档欺骗 | dist/index.js:68 |
| 低危 | Undefined export reference 文档欺骗 | execute.js:7 |
| 资源类型 | 声明权限 | 推断权限 | 状态 | 证据 |
|---|---|---|---|---|
| 浏览器 | READ | READ | ✓ 一致 | Playwright CDP connection to existing browser |
| 浏览器 | WRITE | WRITE | ✓ 一致 | launchPersistentContext creates new Brave instance |
| 文件系统 | READ | READ | ✓ 一致 | Accesses browser userDataDir via Playwright for session persistence |
| 命令执行 | NONE | NONE | — | No subprocess or shell execution detected |
| 网络访问 | NONE | READ | ✓ 一致 | Only connects to x.com and facebook.com for scraping |
3 项发现
中危 外部 URL 外部 URL
https://twitter.com/$ dist/index.js:27 中危 外部 URL 外部 URL
https://www.facebook.com/$ dist/index.js:45 中危 外部 URL 外部 URL
https://clawhub.com/skills/brave-loggedin-tag-browsing skill.json:98 目录结构
12 文件 · 61.3 KB · 1731 行 JavaScript 5f · 628L
JSON 4f · 433L
Markdown 2f · 382L
TypeScript 1f · 288L
├─
▾
dist
│ └─
index.js
JavaScript
├─
cli.js
JavaScript
├─
execute.js
JavaScript
├─
index.js
JavaScript
├─
index.ts
TypeScript
├─
package-lock.json
JSON
├─
package.json
JSON
├─
README.md
Markdown
├─
skill.json
JSON
├─
SKILL.md
Markdown
├─
test-facebook.js
JavaScript
└─
tsconfig.json
JSON
依赖分析 1 项
| 包名 | 版本 | 来源 | 已知漏洞 | 备注 |
|---|---|---|---|---|
playwright | ^1.58.2 | npm | 否 | Version has caret range, recommend exact pinning |
安全亮点
✓ No shell execution or subprocess usage
✓ No credential harvesting or environment variable access
✓ No data exfiltration to external servers
✓ No base64 encoding or obfuscation
✓ No remote script download (curl|bash, wget|sh)
✓ Uses legitimate Playwright library for browser automation
✓ Documentation accurately describes the scraping functionality
✓ Only accesses publicly available social media data
✓ No supply chain risks - uses well-known playwright package with version pinned