bluebubbles

Warn

Audited by Socket on Sep 17, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill’s capabilities are broadly aligned with its stated purpose: it is an iMessage/BlueBubbles action wrapper and does not include hidden installs, shell execution, or obvious exfiltration logic. Risk comes from scope and actionability: it can send and modify real messages on the user’s behalf, and it forwards message content plus gateway credentials to a configurable BlueBubbles server. That makes it high risk operationally, but not malicious based on the provided evidence.

Confidence: 90%Severity: 74%
Audit Metadata
Analyzed At
Sep 17, 2026, 07:54 PM
Package URL
pkg:socket/skills-sh/firecrawl%2Fopenclaw%2Fbluebubbles%2F@395dbbbdd0898ad8e8d58392a69a30709513761b88d85e6028ee3c5f90df94b3
Security Audit — socket — bluebubbles