Warn
Audited by Socket on Aug 1, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s purpose matches its capabilities, but it relies on an under-specified external daemon and local wrapper scripts with no documented, verifiable install provenance in the skill itself. Because the binary can access sensitive WhatsApp session and message data, the unclear supply chain is the main risk driver rather than confirmed malicious behavior.
Confidence: 84%Severity: 78%
Audit Metadata