Webfetch Md
PassAudited by VirusTotal on May 12, 2026.
Findings (1)
The skill's core functionality involves making network requests to arbitrary URLs provided by the user or agent via `fetch` in `index.js`. While this capability is essential for its stated purpose of fetching web pages, it introduces an inherent Server-Side Request Forgery (SSRF) risk if the OpenClaw agent operates within an environment that has access to sensitive internal networks. There is no evidence of malicious intent, such as data exfiltration, persistence mechanisms, or shell injection vulnerabilities in `cli.js` or `SKILL.md`.
