beeper-whatsapp

Warn

Audited by Socket on Aug 13, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/beeper

No strong evidence of embedded malware (no obfuscation, no eval/exec, no persistence, no covert network exfiltration to third-party domains). The module is nevertheless security-sensitive: it unconditionally sends a bearer token to whatever host BASE_URL points to (via BEEPER_API_URL), provides a powerful cmd_raw() escape hatch for arbitrary API calls, and can copy local files during download when file:// URLs are involved, writing to user-chosen destinations that may overwrite existing files. This warrants hardening and careful operational controls but does not, by itself, indicate intentional malicious behavior.

Confidence: 72%Severity: 56%
Audit Metadata
Analyzed At
Aug 13, 2026, 06:57 AM
Package URL
pkg:socket/skills-sh/nikhilbhansali%2Fbeeper-whatsapp-skill%2Fbeeper-whatsapp%2F@0ec47bb40aa89ea9545e4d9a589b26542e05fa87
Security Audit — socket — beeper-whatsapp