crawl4ai-fetch

Warn

Audited by Socket on Apr 24, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s core function is coherent, but its default behavior sends user-requested URLs, fetched content, and optionally bearer tokens to an unverified third-party domain while describing itself as self-hosted Crawl4AI. The main risk is data and credential routing to a backend with unclear ownership, not confirmed malware.

Confidence: 88%Severity: 69%
Audit Metadata
Analyzed At
Apr 24, 2026, 02:19 AM
Package URL
pkg:socket/skills-sh/ichuan%2Fskills%2Fcrawl4ai-fetch%2F@0c85a2f996cd3dff510e0dc7ed27113cbf506290