web-content-downloader
Warn
Audited by Socket on Mar 28, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The core purpose is coherent, but the skill's primary method sends user-requested URLs and content through Jina's third-party hosted reader, and the fallback references an MCP fetch path with unclear official provenance. Scope is otherwise proportionate, with moderate risk from indirect prompt injection and third-party data routing rather than clear malware behavior.
Confidence: 85%Severity: 56%
Audit Metadata