web-search
Warn
Audited by Socket on Mar 18, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill’s purpose broadly matches its capabilities, but it relies on an external same-org CLI with curl|sh installation, routes search/extraction traffic through inference.sh rather than directly to Tavily/Exa, forwards credentials into that CLI, and instructs transitive skill installation. This is not confirmed malware, but it carries meaningful supply-chain, credential-trust, and prompt-injection risk.
Confidence: 87%Severity: 66%
Audit Metadata