add-whatsapp

Warn

Audited by Socket on Mar 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The skill is broadly consistent with its stated purpose: adding WhatsApp as a channel requires auth credentials, chat registration, and new channel code. The main risk is install/execution trust: it fetches and merges code from an external GitHub repo, then installs dependencies and executes setup scripts, which is a real supply-chain risk if the repo provenance is not independently verified. No clear credential exfiltration, stealth, or unrelated capability expansion is present, so this is better classified as suspicious supply-chain exposure than malware.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Mar 29, 2026, 07:40 AM
Package URL
pkg:socket/skills-sh/qwibitai%2Fnanoclaw-skills%2Fadd-whatsapp%2F@451dd5e086fabf0d696155056e96400ddfc08bb1