web-research
Warn
Audited by Socket on Apr 10, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The stated purpose is legitimate and there is no evidence of malicious installers, credential harvesting, or third-party routing, but the skill is over-permissioned for web research: it combines untrusted web intake with Write and Bash access, which creates a high indirect prompt-injection risk. The missing `AskUserQuestion` tool also shows instruction/tool mismatch.
Confidence: 85%Severity: 74%
Audit Metadata