webcmd-usage
Warn
Audited by Socket on Aug 1, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
Likely benign as a Webcmd orientation skill: the official npm install path is coherent with the stated purpose, and the guidance includes sensible auth handoff rules. The main risk comes from Webcmd's extensibility: plugin installs from variable git/local sources, external CLI passthrough, and browser-driven authenticated actions widen the supply-chain and operational footprint, so the skill is better classified as suspicious/medium-risk rather than malicious.
Confidence: 84%Severity: 62%
Audit Metadata