jobber

Warn

Audited by Socket on Jul 10, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s purpose is plausible, but its actual footprint is disproportionate and poorly verified. It routes high-value Jobber browser/session credentials into an unofficial CLI with unclear provenance and uses private API access patterns instead of the documented public API flow. Because an unverifiable CLI may receive credentials, this should be treated as high security risk even without proof of malicious intent.

Confidence: 84%Severity: 86%
Audit Metadata
Analyzed At
Jul 10, 2026, 03:09 AM
Package URL
pkg:socket/skills-sh/danielgwilson%2Fjobber-cli%2Fjobber%2F@40bce0a9bdb54abaf9b45a65da8e66889c9ee372be230acd8c1c8510194ab192
Security Audit — socket — jobber