xfetch-web
Warn
Audited by Socket on Sep 23, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the overall behavior mostly fits a web-fetch skill and there is no obvious malware pattern, but the trust boundary is broader than stated because all page reads are routed through a remote Qiniu endpoint and the base URL is overrideable, allowing bearer-token and content forwarding to another host. Main risk is data-flow trust and endpoint provenance, not command injection.
Confidence: 84%Severity: 52%
Audit Metadata