whereby
Warn
Audited by Socket on May 2, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill's stated purpose fits Whereby automation, and the install source is an official npm package, but it introduces a third-party integration layer that receives authentication and mediates all Whereby access. This is not confirmed malware, but it is a medium-risk trust and data-flow expansion compared with a direct Whereby integration.
Confidence: 84%Severity: 56%
Audit Metadata