web-content-downloader

Warn

Audited by Socket on Mar 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The core purpose is coherent, but the skill's primary method sends user-requested URLs and content through Jina's third-party hosted reader, and the fallback references an MCP fetch path with unclear official provenance. Scope is otherwise proportionate, with moderate risk from indirect prompt injection and third-party data routing rather than clear malware behavior.

Confidence: 85%Severity: 56%
Audit Metadata
Analyzed At
Mar 28, 2026, 12:48 PM
Package URL
pkg:socket/skills-sh/ForceInjection%2Fawesome-skills%2Fweb-content-downloader%2F@0ff8d251bfb7cfd2e52ade12c62a5985989d1ca1