use-tinyfish

Warn

Audited by Socket on Sep 14, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is purpose-aligned and uses an official same-org npm package and TinyFish-owned service endpoints, so there is no strong malware signal. However, it forwards user requests and API credentials to an external CLI/service and enables arbitrary website automation plus ingestion of untrusted web content, creating medium security risk disproportionate to a simple search/fetch helper.

Confidence: 90%Severity: 50%
Audit Metadata
Analyzed At
Sep 14, 2026, 03:09 PM
Package URL
pkg:socket/skills-sh/tinyfish-io%2Ftinyfish-cookbook%2Fuse-tinyfish%2F@a9d891f05b36a0bc4a63622179e1fccda8bd47bdc2bc3af9d908296bccd1df3a
Security Audit — socket — use-tinyfish