websh

Warn

Audited by Socket on Jun 19, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's core capability matches its stated web-navigation purpose, and there is no evident supply-chain or credential-harvesting behavior. However, it grants the agent broad autonomy to interpret intent, fetch arbitrary URLs, and recursively prefetch linked pages in the background, creating meaningful prompt-injection and uncontrolled network-action risk that is disproportionate to a simple browsing helper.

Confidence: 87%Severity: 62%
Audit Metadata
Analyzed At
Jun 19, 2026, 11:41 PM
Package URL
pkg:socket/skills-sh/nicepkg%2Fauto-company%2Fwebsh%2F@9a0780b6bdf4ce399402430f9e0bc1637f2848c49b840772c7168952afb702df
Security Audit — socket — websh