web-research

Warn

Audited by Socket on Apr 10, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated purpose is legitimate and there is no evidence of malicious installers, credential harvesting, or third-party routing, but the skill is over-permissioned for web research: it combines untrusted web intake with Write and Bash access, which creates a high indirect prompt-injection risk. The missing `AskUserQuestion` tool also shows instruction/tool mismatch.

Confidence: 85%Severity: 74%
Audit Metadata
Analyzed At
Apr 10, 2026, 07:28 AM
Package URL
pkg:socket/skills-sh/duc01226%2Feasyplatform%2Fweb-research%2F@ff5a7362341b1282d6bdea686ca2bbf576c13a3e