web-to-markdown

Warn

Audited by Socket on Aug 21, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated purpose is coherent, but the skill depends on building and running an unverifiable local web2md CLI from a workspace path that cannot be tied to a verified same-org release process. Data flows are otherwise proportionate for webpage-to-Markdown conversion, with no explicit credential harvesting or proxy routing, but the unverified executable and optional access to browser profile state make this a high security-risk skill.

Confidence: 84%Severity: 78%
Audit Metadata
Analyzed At
Aug 21, 2026, 04:05 PM
Package URL
pkg:socket/skills-sh/softaworks%2Fagent-skills%2Fweb-to-markdown%2F@6b02cda0b2c4d764ecfeccec4e14fdca7dc6011dce0cda6282778a45834d2912
Security Audit — socket — web-to-markdown