wjs-looping-feedback

Warn

Audited by Socket on Jun 13, 2026

4 alerts found:

Anomalyx2Securityx2
AnomalyLOW
references/install.md

The provided content does not itself contain explicit malicious code, but it operationalizes a powerful supply-chain pattern: it injects a runtime widget into a production site, installs a GitHub Actions workflow, stores LLM/API credentials as secrets, and enables automated commits to main with potential live deployment. Because the actual widget/workflow/runtime modules are not present in this snippet, malicious intent (e.g., exfiltration/backdoor behavior) cannot be confirmed or ruled out from this fragment alone; however, the described attack surface and blast radius are significant and warrant thorough inspection of the referenced assets before use.

Confidence: 100%Severity: 60%
AnomalyLOW
assets/feedback.yml

This workflow does not show explicit malware in the YAML fragment, but it implements a high-impact LLM-driven CI agent that can write files and execute shell commands (Bash) and then automatically commits and pushes to main based on user-controlled issue content. This is a substantial supply-chain/automation security risk and warrants reviewing the tool sandbox guarantees of the external LLM action and the safety of the local .feedback scripts (especially how they handle untrusted text and LLM outputs).

Confidence: 100%Severity: 60%
SecurityMEDIUM
SKILL.md
SecurityMEDIUM
README.md
Audit Metadata
Analyzed At
Jun 13, 2026, 09:11 AM
Package URL
pkg:socket/skills-sh/jianshuo%2Fclaude-skills%2Fwjs-looping-feedback%2F@4b9f69396d625f47b1741728cf5980876255ca8bee4dfc4e53ed16edd10286d4
Security Audit — socket — wjs-looping-feedback