Correction to v0.1.0's documentation. v0.1.0 described the captcha path as wired in and bounded, and did not say what buying a solve actually achieves here. Measured now: on this site, from a datacenter address, a paid Turnstile token is refused — the challenge is captured and solved correctly and Cloudflare does not accept it (3 tokens, 3 refusals). If you read v0.1.0's README and bought solving to get past the block, that is not what will get you in. A residential exit is, and it costs less.
An audit against this project family's own checklist, section by section, executing each claim rather than re-reading it. Three defects, all found by running a path that had never been run, and none of them visible to the 356 green offline checks v0.1.0 shipped with.
Fixed
SOLVES_PER_PAGEwas not enforced, and it is a money limit. Every engine calls the solver twice per attempt — once before the page is classified, once after — and only the second was counted. From a datacenter address, where a real Cloudflare challenge renders on every fetch: one page bought three Turnstile solves. Both call sites are now counted; the same run buys one.- A dead proxy was reported as a plain "gave up loading". The reason was computed and logged on rotation with a pool, then dropped without one — the single-
--proxycase, which is the common one.--proxy http://127.0.0.1:9said nothing about the proxy. All three engines now name it. - Two inherited claims that were false about this site.
scraper_api_client.pyprinted a sibling repo's measurement as this repo's; replaced with what was measured here (the Scraper API's own exits get upstream 403 and 11,825 bytes; the same task through a Scraping Browser session returns 200, 610,897 bytes and 37 job rows).captcha_solver.py's docstring described another site's defences and called itself load-bearing here. - The README said
angel.co's old routes no longer exist. They do —angel.co/role/r/software-engineerreturns the same page. The host is still refused so one job never appears under two spellings, but the stated reason is now the true one.
Verified, by running it
The fingerprint path applies its user agent, locale (en-US, not en-{country}) and timezone to the real browser · a failing API call does not leak the key · credentials never reach the browser's argv · the flag set covers all 28 family-contract flags · pip check passes per engine venv · the Scraping Browser path serves this site · --dump-html writes on success · exit 3 and exit 4 are distinct · no column is null on every row of every run · all three engines return 52 identical rows after the edits.
373 offline checks, CI green on Python 3.9 and 3.12, all three engine-smoke jobs and the Docker build.