webmcp-gen

Warn

Audited by Socket on Jun 18, 2026

2 alerts found:

AnomalySecurity
AnomalyLOW
scripts/validate.mjs

This module behaves like a test/validation harness, not a typical malware loader. However, it contains high-impact trust-boundary actions: it injects and executes artifact-controlled JavaScript (webmcp.init.js) in a headless browser and navigates to an unvalidated URL from manifest.json. It also writes tool outputs/errors verbatim into JSON and Markdown reports without sanitization, which can enable report poisoning in downstream tooling. If artifacts/manifests are not fully trusted, the security risk is elevated despite the absence of explicit malicious behavior in this file.

Confidence: 64%Severity: 58%
SecurityMEDIUM
scripts/compile.mjs
Audit Metadata
Analyzed At
Jun 18, 2026, 11:19 PM
Package URL
pkg:socket/skills-sh/browserbase%2Fskills%2Fwebmcp-gen%2F@0a6ee9191ccb0a4e8315578f84ce65ad2c9bc46845c462b43524260b93d97ec5
Security Audit — socket — webmcp-gen