markdown-fetch
Warn
Audited by Socket on Mar 28, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the core purpose is plausible, but the skill quietly routes user-requested browsing through a third-party service with separate operators/subprocessors, and it references an unverifiable local wrapper. The biggest concerns are third-party data routing, automatic ingestion of untrusted web content, and undocumented credential handling for protected pages. Not confirmed malware, but the data-flow and trust boundaries are insufficiently transparent for a default URL-fetch skill.
Confidence: 86%Severity: 64%
Audit Metadata