web-search
Audited by Socket on Aug 6, 2026
2 alerts found:
AnomalySecurityThis fragment is documentation, not malicious executable code. The principal concerns are (1) supply-chain risk from instructing installs via `npx` without version pinning and (2) privacy/data-handling risk because the documented workflow sends user queries/questions/URLs to third-party search/extraction providers (and optionally writes outputs to local files). No direct indicators of embedded malware, obfuscation, or credential theft are present in the provided content.
SUSPICIOUS: the skill’s search purpose is plausible, but its footprint is broader than a normal direct API integration. Main concerns are transitive skill installation, same-org but risky remote installer patterns, broad CLI delegation via `Bash(belt *)`, and routing authenticated queries/content through inference.sh as an intermediary rather than directly to Tavily/Exa/OpenRouter.