web-to-markdown
Warn
Audited by Socket on Aug 21, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The stated purpose is coherent, but the skill depends on building and running an unverifiable local web2md CLI from a workspace path that cannot be tied to a verified same-org release process. Data flows are otherwise proportionate for webpage-to-Markdown conversion, with no explicit credential harvesting or proxy routing, but the unverified executable and optional access to browser profile state make this a high security-risk skill.
Confidence: 84%Severity: 78%
Audit Metadata