use-tinyfish
Warn
Audited by Socket on Sep 14, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill is purpose-aligned and uses an official same-org npm package and TinyFish-owned service endpoints, so there is no strong malware signal. However, it forwards user requests and API credentials to an external CLI/service and enables arbitrary website automation plus ingestion of untrusted web content, creating medium security risk disproportionate to a simple search/fetch helper.
Confidence: 90%Severity: 50%
Audit Metadata