jobber
Warn
Audited by Socket on Jul 10, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s purpose is plausible, but its actual footprint is disproportionate and poorly verified. It routes high-value Jobber browser/session credentials into an unofficial CLI with unclear provenance and uses private API access patterns instead of the documented public API flow. Because an unverifiable CLI may receive credentials, this should be treated as high security risk even without proof of malicious intent.
Confidence: 84%Severity: 86%
Audit Metadata