webcmd-usage

Warn

Audited by Socket on Aug 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

Likely benign as a Webcmd orientation skill: the official npm install path is coherent with the stated purpose, and the guidance includes sensible auth handoff rules. The main risk comes from Webcmd's extensibility: plugin installs from variable git/local sources, external CLI passthrough, and browser-driven authenticated actions widen the supply-chain and operational footprint, so the skill is better classified as suspicious/medium-risk rather than malicious.

Confidence: 84%Severity: 62%
Audit Metadata
Analyzed At
Aug 1, 2026, 06:47 AM
Package URL
pkg:socket/skills-sh/agentrhq%2Fwebcmd%2Fwebcmd-usage%2F@cf53468efb4c41be1c302490ada369acc1cacbea61b33c58734ea3474e16ae69
Security Audit — socket — webcmd-usage