wema-bmc

Fail

Audited by Socket on Jul 2, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS: The endpoints and API flow are consistent with the stated BMC purpose and appear to target official BMC SaaS infrastructure, so this is not primarily a supply-chain or proxy-harvesting skill. However, it embeds plaintext production credentials for a bank service account, grants broad access to sensitive internal records, and enables real write actions in a live system without guardrails. The main risk is severe secret exposure and disproportionate access, not deceptive installer behavior.

Confidence: 94%Severity: 96%
Audit Metadata
Analyzed At
Jul 2, 2026, 07:13 PM
Package URL
pkg:socket/skills-sh/DrOlu%2Fagent-skills%2Fwema-bmc%2F@9f1ada0db56f21ceb8d1c2cd8e04cf37ebe9529ee114e2a6895ddfad060a5643
Security Audit — socket — wema-bmc