parallel-web-extract
Audited by Socket on Mar 11, 2026
1 alert found:
MalwareThe skill's stated purpose (URL content extraction using parallel-cli) aligns with a content-fetching workflow, but the footprint includes high-risk patterns: direct curl|bash install from an external domain (unverifiable), reliance on an external binary, and potential handling of credentials (PARALLEL_API_KEY). The data flow (fetching arbitrary URLs and printing verbatim) is normal for an extractor but increases exposure surface. Overall, the footprint is suspicious due to the download-execute pattern and unverifiable dependency, and could expose users to supply-chain and credential risks. Treat as SUSPICIOUS with caution; require tightened install provenance, signed checksums, and explicit, minimal data handling guarantees before deeming Benign.