web-search

Warn

Audited by Socket on Mar 3, 2026

2 alerts found:

AnomalySecurity
AnomalyLOW
README.md

The fragment presents a sound concept for a multi-engine search tool with sensible fallback behavior and structured outputs. No evidence of malware, backdoors, or credential harvesting is observed in the description. Primary concerns are legal/privacy considerations and potential logging/exfiltration through scraping pipelines. Recommend proceeding to review actual source code and dependency chain (including Playwright usage, logging, and data protection) for a comprehensive security assessment; otherwise, treat as low-risk-to-moderate risk depending on deployment controls.

Confidence: 75%Severity: 60%
SecurityMEDIUM
SKILL.md

The package implements a plausible web-search and crawling capability via scraping and browser automation without API keys. I found no direct evidence of embedded backdoors, hard-coded credentials, or explicit exfiltration code in the provided manifest. However, there are meaningful supply-chain and operational risks: runtime download-and-execute of Chromium, unpinned/unknown third-party dependencies, and the ability to crawl arbitrary URLs (SSRF/exfiltration potential). The mention of bypassing anti-bot protections indicates aggressive scraping techniques that may be legally/ethically problematic. Recommendation: treat as moderate risk — audit third-party packages and code, pin versions, sandbox Playwright, restrict crawl targets, and monitor outbound network activity prior to use.

Confidence: 98%Severity: 75%
Audit Metadata
Analyzed At
Mar 3, 2026, 06:57 AM
Package URL
pkg:socket/skills-sh/yejinlei%2Fweb-search-skill%2Fweb-search%2F@00b2ab6b694f9f0100d4679e9765034fe108a7ac