minion-fetch

Warn

Audited by Socket on Mar 25, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated purpose matches URL fetching, but the skill relies on an unverifiable, unpinned `npx` package whose publisher/source relationship could not be confirmed. It also enables fetching arbitrary untrusted content with optional processing, which is broader and riskier than a tightly scoped retrieval skill. No direct credential harvesting or malicious exfiltration endpoint is shown, but installer trust and external-content handling make this a high security-risk skill.

Confidence: 84%Severity: 74%
Audit Metadata
Analyzed At
Mar 25, 2026, 01:25 AM
Package URL
pkg:socket/skills-sh/fboldo%2Fminion-kit%2Fminion-fetch%2F@ae74eb0613a4c390240cd3311d73a503c3b0276c
Security Audit — socket — minion-fetch