web-search

Warn

Audited by Socket on Apr 9, 2026

2 alerts found:

AnomalySecurity
AnomalyLOW
SKILL.md

SUSPICIOUS. The stated purpose matches a web-search capability, and the requested credentials are proportionate, but install trust and backend/data-flow transparency are weak: the skill relies on unseen local executables/scripts and unspecified search endpoints. Main risk is medium supply-chain uncertainty plus high indirect prompt-injection exposure from processing untrusted web content.

Confidence: 80%Severity: 62%
SecurityMEDIUM
install.sh

No direct malicious behavior is evident in this Bash fragment beyond installation/bootstrap logic, but the script performs high-risk supply-chain operations: it executes an unauthenticated remote installer (`curl ... | sh`) and installs additional code based on a remote requirements URL without visible pinning or integrity verification. Given the cred-related tooling implied by usage text, compromise of the remote installer/requirements could have elevated impact. This should be reviewed and mitigated with pinned versions/lockfiles and integrity checks before use.

Confidence: 70%Severity: 82%
Audit Metadata
Analyzed At
Apr 9, 2026, 11:58 PM
Package URL
pkg:socket/skills-sh/devskale%2Fskale-skills%2Fweb-search%2F@95262aef216e394b62df919d1f9cb65fd1898bed