web-search

Warn

Audited by Socket on Mar 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the install path is benign and well-aligned with the stated purpose, but the skill materially increases agent risk by proactively searching and fetching arbitrary web content. This is a coherent web-search skill, not malware, yet it is high-risk from indirect prompt injection and untrusted-content exposure.

Confidence: 93%Severity: 58%
Audit Metadata
Analyzed At
Mar 29, 2026, 03:32 PM
Package URL
pkg:socket/skills-sh/ysm-dev%2Fskills%2Fweb-search%2F@ab1d54194f3f259733532026ed55045474e06b86