wordpress-uploader

Warn

Audited by Socket on Apr 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

This skill is mostly coherent with its stated WordPress publishing purpose and uses official WordPress auth/API concepts, but it relies on unreviewed local Python wrapper scripts and direct ~/.env credential access. That makes it suspicious-but-not-malicious: the main risk is unverifiable local execution around sensitive publishing credentials, not obvious exfiltration or deceptive routing.

Confidence: 80%Severity: 58%
Audit Metadata
Analyzed At
Apr 1, 2026, 05:59 AM
Package URL
pkg:socket/skills-sh/notque%2Fclaude-code-toolkit%2Fwordpress-uploader%2F@17e2a1723c986228ae5a4b2e7514b569a784a515