wordpress-uploader
Warn
Audited by Socket on Apr 1, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
This skill is mostly coherent with its stated WordPress publishing purpose and uses official WordPress auth/API concepts, but it relies on unreviewed local Python wrapper scripts and direct ~/.env credential access. That makes it suspicious-but-not-malicious: the main risk is unverifiable local execution around sensitive publishing credentials, not obvious exfiltration or deceptive routing.
Confidence: 80%Severity: 58%
Audit Metadata