builderbot-code-skill
Warn
Audited by Socket on Sep 17, 2026
1 alert found:
AnomalyAnomalypatterns.md
LOWAnomalyLOW
patterns.md
No clear malware or supply-chain attack behavior is present. The fragment documents normal bot functionality, but the REST examples are potentially insecure if deployed as shown: unauthenticated endpoints permit message sending, flow triggering, and blacklist modification, while caller-controlled media URLs or paths may create SSRF or file-access risk depending on provider implementation. Location logging also presents a privacy consideration.
Confidence: 94%Severity: 66%
Audit Metadata