web-search

Warn

Audited by Socket on Mar 13, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The core purpose is coherent, but the skill materially increases agent risk by combining open-ended web research with Bash/WebFetch access, creating strong indirect prompt-injection exposure. It also forwards optional search activity and API keys through third-party SerpApi and references an unverifiable local `alma` config command, so overall risk is medium even without clear malware behavior.

Confidence: 89%Severity: 69%
Audit Metadata
Analyzed At
Mar 13, 2026, 11:44 AM
Package URL
pkg:socket/skills-sh/ninehills%2Fskills%2Fweb-search%2F@41b4d47a246b04d47a212dee61239cb88a401964