jfb-action-external-api

Warn

Audited by Socket on Sep 9, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is internally consistent as a developer guide for JetFormBuilder external API actions, with no malicious installer or hidden execution behavior. However, its core purpose is to transmit form data and stored API credentials to arbitrary third-party endpoints, including sensitive integrations like CRMs, LLMs, webhooks, and payment processors, so the security risk is medium even though the content itself appears benign.

Confidence: 90%Severity: 58%
Audit Metadata
Analyzed At
Sep 9, 2026, 07:07 PM
Package URL
pkg:socket/skills-sh/lonsdale201%2Fwp-agent-skills%2Fjfb-action-external-api%2F@2d091df077365fb97970e6d63f21e437975d0b88d506cb60c3b3847303e8af9c
Security Audit — socket — jfb-action-external-api