builderbot-code-skill

Warn

Audited by Socket on Sep 17, 2026

1 alert found:

Anomaly
AnomalyLOW
patterns.md

No clear malware or supply-chain attack behavior is present. The fragment documents normal bot functionality, but the REST examples are potentially insecure if deployed as shown: unauthenticated endpoints permit message sending, flow triggering, and blacklist modification, while caller-controlled media URLs or paths may create SSRF or file-access risk depending on provider implementation. Location logging also presents a privacy consideration.

Confidence: 94%Severity: 66%
Audit Metadata
Analyzed At
Sep 17, 2026, 07:01 AM
Package URL
pkg:socket/skills-sh/leifermendez%2Fskill-builderbot-code%2Fbuilderbot-code-skill%2F@cb3dad34e75cbdd6c0062f458ca2a1ebb44f809c03e2dad91977847c3fe0ec58
Security Audit — socket — builderbot-code-skill