wema-bmc
Fail
Audited by Socket on Jul 2, 2026
1 alert found:
MalwareMalwareSKILL.md
HIGHMalwareHIGH
SKILL.md
SUSPICIOUS: The endpoints and API flow are consistent with the stated BMC purpose and appear to target official BMC SaaS infrastructure, so this is not primarily a supply-chain or proxy-harvesting skill. However, it embeds plaintext production credentials for a bank service account, grants broad access to sensitive internal records, and enables real write actions in a live system without guardrails. The main risk is severe secret exposure and disproportionate access, not deceptive installer behavior.
Confidence: 94%Severity: 96%
Audit Metadata