web-search

Warn

Audited by Socket on Jun 19, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the stated purpose matches web research, but the implementation depends on inference.sh as an intermediary for Tavily/Exa/OpenRouter operations instead of direct official APIs, and it requires transitive skill installation. This is not confirmed malware, but it carries medium risk from third-party data routing, credential forwarding potential, and supply-chain trust expansion.

Confidence: 82%Severity: 64%
Audit Metadata
Analyzed At
Jun 19, 2026, 02:16 AM
Package URL
pkg:socket/skills-sh/halt-catch-fire%2Fskills%2Fweb-search%2F@7d064e7cf327ecb798093cd068723dc6ac738450c5cb0251246a67a98ac0369c
Security Audit — socket — web-search