website-to-hyperframes

Warn

Audited by Socket on Aug 20, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core behavior matches the stated purpose and uses an official same-org npm tool, so this is not fundamentally incompatible or overtly malicious. The main risks are unpinned `npx` supply-chain exposure, transitive skill loading, and especially fetching arbitrary websites while the agent also has write/exec capabilities, which creates meaningful indirect prompt-injection risk.

Confidence: 86%Severity: 58%
Audit Metadata
Analyzed At
Aug 20, 2026, 08:42 AM
Package URL
pkg:socket/skills-sh/onewave-ai%2Fcrest%2Fwebsite-to-hyperframes%2F@3ff608ac01b8c193dbc3458dc4b81be47febbe0ee3e8b37643e5abc899a10bfc
Security Audit — socket — website-to-hyperframes