web-search
Warn
Audited by Socket on May 27, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the stated purpose matches web research, but the implementation depends on inference.sh as an intermediary for Tavily/Exa/OpenRouter operations instead of direct official APIs, and it requires transitive skill installation. This is not confirmed malware, but it carries medium risk from third-party data routing, credential forwarding potential, and supply-chain trust expansion.
Confidence: 82%Severity: 64%
Audit Metadata