web-fetch

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's capabilities broadly match its stated HTTP/API-testing purpose, so it is not fundamentally incompatible or overtly malicious. However, it expands the agent to arbitrary outbound network access, includes an unpinned `npx -y` MCP server install with some package-name inconsistency, forwards secrets to user-chosen endpoints, and shows TLS-bypass usage; these combined issues make it higher-risk than a simple documentation skill.

Confidence: 88%Severity: 58%
Audit Metadata
Analyzed At
Mar 18, 2026, 07:16 AM
Package URL
pkg:socket/skills-sh/phuetz%2Fcode-buddy%2Fweb-fetch%2F@837525ce0b5f8aa48b2f1d72fd5ca62b197296ef