wzrrd-publish

Warn

Audited by Socket on May 19, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s stated purpose and file-upload behavior are coherent, but its trust model is not: it requires installing an unverifiable CLI through an unpinned curl|bash script, and that CLI later handles login-derived tokens and uploads user files. With no verified official repo, registry package, checksums, or release history in the provided evidence, the install and credential-forwarding risks are disproportionate.

Confidence: 85%Severity: 84%
Audit Metadata
Analyzed At
May 19, 2026, 11:04 AM
Package URL
pkg:socket/skills-sh/joelhooks%2Fwzrrd-sh-cli%2Fwzrrd-publish%2F@764d1ab8bb2a372127ced733dad191f1ddeeb70e
Security Audit — socket — wzrrd-publish