webmcp-sdk-skill
Warn
Audited by Socket on Sep 24, 2026
2 alerts found:
Anomalyx2Anomalyrules/uni-app.md
LOWAnomalyLOW
rules/uni-app.md
No clear malware or concealed malicious behavior is present. The main security concern is the remote-control interface: if the session URL is accessible to an unintended party, that party may read application data, alter the cart, or trigger a purchase. Avoid fixed/reused session IDs and enforce authentication, authorization, and confirmation for sensitive tools.
Confidence: 97%Severity: 58%
Anomalyrules/use-next-agent.md
LOWAnomalyLOW
rules/use-next-agent.md
No clear malware or unauthorized data theft behavior is present in this documentation example. It does contain a potential XSS risk from rendering unsanitized Markdown with raw HTML enabled, and demonstrates a client-side API key-like value that should not be used for real secrets.
Confidence: 97%Severity: 55%
Audit Metadata