confluence-browser-fetch

Warn

Audited by Socket on May 8, 2026

1 alert found:

Security
SecurityMEDIUM
scripts/confluence-browser-fetch.js

No clear indicators of intentional malware (no obfuscation, no persistence, no command execution, no overt third-party exfiltration). However, this module contains a significant security weakness: it fetches arbitrary user-supplied http(s) URLs while attaching authenticated Confluence cookies, enabling credential leakage (SSRF-with-credentials) and potentially redirect-assisted cookie disclosure. This should be treated as a security-alert condition; the URL-fetching feature should be allowlisted to the configured Atlassian site or otherwise prevented from sending cookies to untrusted destinations.

Confidence: 74%Severity: 82%
Audit Metadata
Analyzed At
May 8, 2026, 08:26 PM
Package URL
pkg:socket/skills-sh/aholbreich%2Fagent-skills%2Fconfluence-browser-fetch%2F@a54f9901bd8c6f0227729e0811abf0f4a37e5683