wren-http-api

Warn

Audited by Socket on Mar 26, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core HTTP JSON-RPC behavior is consistent with the stated purpose and targets a local Wren server, but the skill adds moderate trust risk through a silent remote version check, transitive skill-install guidance via a third-party CLI, and an unpinned `latest` container image. No clear credential harvesting or off-target exfiltration is present.

Confidence: 84%Severity: 52%
Audit Metadata
Analyzed At
Mar 26, 2026, 05:03 PM
Package URL
pkg:socket/skills-sh/Canner%2Fwren-engine%2Fwren-http-api%2F@467aed217d03c7b6be4e72b9201c5f13ccee55e8