wpds

Warn

Audited by Socket on Aug 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The provided skill is mostly a benign catalogue entry, but it does not implement its stated workflow and instead redirects users to install an upstream bundle. That transitive installation step, combined with the mismatched upstream repo reference and split trust between WordPress content and a separate skills installer ecosystem, creates moderate supply-chain risk even though there is no direct credential handling or exfiltration in this file.

Confidence: 90%Severity: 52%
Audit Metadata
Analyzed At
Aug 2, 2026, 03:59 PM
Package URL
pkg:socket/skills-sh/hosseinmirzapur%2Fopencode-skills%2Fwpds%2F@da727a8bb8cbd11337a42eb0c70a70a04e0291b20df55cd9aefe5662ee2e9078
Security Audit — socket — wpds