xfetch-web

Warn

Audited by Socket on Sep 23, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the overall behavior mostly fits a web-fetch skill and there is no obvious malware pattern, but the trust boundary is broader than stated because all page reads are routed through a remote Qiniu endpoint and the base URL is overrideable, allowing bearer-token and content forwarding to another host. Main risk is data-flow trust and endpoint provenance, not command injection.

Confidence: 84%Severity: 52%
Audit Metadata
Analyzed At
Sep 23, 2026, 01:57 AM
Package URL
pkg:socket/skills-sh/qiniu%2Fskills%2Fxfetch-web%2F@bde3978d1ba39317bbf15f23d4738c863afdcd079b77509e689ebd4617ca4ac0