whatsapp

Warn

Audited by Socket on Aug 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s purpose matches its capabilities, but it relies on an under-specified external daemon and local wrapper scripts with no documented, verifiable install provenance in the skill itself. Because the binary can access sensitive WhatsApp session and message data, the unclear supply chain is the main risk driver rather than confirmed malicious behavior.

Confidence: 84%Severity: 78%
Audit Metadata
Analyzed At
Aug 1, 2026, 01:46 PM
Package URL
pkg:socket/skills-sh/lncitador%2Fwhatsapp-mcp%2Fwhatsapp%2F@4aa32b62c7bee2028c2a9b7a469cfcdbe41f247be8cb37079832ed8db5a7746a
Security Audit — socket — whatsapp