parallel-web-extract

Fail

Audited by Socket on Mar 11, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The skill's stated purpose (URL content extraction using parallel-cli) aligns with a content-fetching workflow, but the footprint includes high-risk patterns: direct curl|bash install from an external domain (unverifiable), reliance on an external binary, and potential handling of credentials (PARALLEL_API_KEY). The data flow (fetching arbitrary URLs and printing verbatim) is normal for an extractor but increases exposure surface. Overall, the footprint is suspicious due to the download-execute pattern and unverifiable dependency, and could expose users to supply-chain and credential risks. Treat as SUSPICIOUS with caution; require tightened install provenance, signed checksums, and explicit, minimal data handling guarantees before deeming Benign.

Confidence: 65%Severity: 65%
Audit Metadata
Analyzed At
Mar 11, 2026, 10:43 PM
Package URL
pkg:socket/skills-sh/parallel-web%2Fparallel-agent-skills%2Fparallel-web-extract%2F@909c535c06eae5fc2518f3a85e56a113a040c10c