web-to-markdown

Warn

Audited by Socket on Apr 7, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the stated purpose matches web extraction, but the skill's default architecture routes browsing through third-party proxy services (r.jina.ai, defuddle.md) instead of fetching directly from origin sites. That makes data flow less trustworthy and, combined with arbitrary external-content ingestion, creates meaningful prompt-injection and privacy risk even without credential access or overtly malicious code.

Confidence: 84%Severity: 62%
Audit Metadata
Analyzed At
Apr 7, 2026, 05:21 AM
Package URL
pkg:socket/skills-sh/rookie-ricardo%2Ferduo-skills%2Fweb-to-markdown%2F@1fc49195df6eb01206e3fda792d16fb1b5c043d1