nimble-web-tools

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This skill/documentation is coherent with its stated purpose (a CLI-based real-time web intelligence tool) and does not contain explicit malicious code or obfuscated payloads. However, it centralizes web fetching and scraped content through a third-party service (Nimbleway) and requires an API key, which creates a moderate supply-chain and data-exfiltration risk: any sensitive data the agent fetches may be sent to the vendor, and --callback/webhook support allows forwarding scraped content to arbitrary endpoints. The tool's advanced features (stealth unblocking, JS rendering, geolocation) and the instruction to prefer the vendor for all web tasks amplify the risk surface. I rate this as not-malicious code-wise but medium security risk due to scope, centralized data flows, and exfiltration capabilities — review vendor trust, privacy policy, and restrict agent permissions before use.

Confidence: 80%Severity: 75%
Audit Metadata
Analyzed At
Mar 18, 2026, 01:01 AM
Package URL
pkg:socket/skills-sh/nimbleway%2Fagent-skills%2Fnimble-web-tools%2F@6d91f348ddc33fa20f587a436d857db101b16436