webmcp-sdk-skill

Warn

Audited by Socket on Sep 24, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
rules/uni-app.md

No clear malware or concealed malicious behavior is present. The main security concern is the remote-control interface: if the session URL is accessible to an unintended party, that party may read application data, alter the cart, or trigger a purchase. Avoid fixed/reused session IDs and enforce authentication, authorization, and confirmation for sensitive tools.

Confidence: 97%Severity: 58%
AnomalyLOW
rules/use-next-agent.md

No clear malware or unauthorized data theft behavior is present in this documentation example. It does contain a potential XSS risk from rendering unsanitized Markdown with raw HTML enabled, and demonstrates a client-side API key-like value that should not be used for real secrets.

Confidence: 97%Severity: 55%
Audit Metadata
Analyzed At
Sep 24, 2026, 09:27 AM
Package URL
pkg:socket/skills-sh/opentiny%2Fagent-skills%2Fwebmcp-sdk-skill%2F@7fa5e546ea7e4078c4070c5c7db70f7138566cfc3b2c63bf01e0867fa73e9437
Security Audit — socket — webmcp-sdk-skill