wails

Fail

Audited by Snyk on Jul 11, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E006: Malicious code pattern detected in skill scripts.

  • Malicious code pattern detected (high risk: 1.00). The docs explicitly recommend embedding an MCP server (WAILS_MCP=1) that lets LLM agents remotely control the app (window control, DOM inspection, bound-method calls) and also document serving HTTP routes from services — both are deliberate remote-access patterns that can be abused as backdoors or for data exfiltration.

Issues (1)

E006
CRITICAL

Malicious code pattern detected in skill scripts.

Audit Metadata
Risk Level
CRITICAL
Analyzed
Jul 11, 2026, 05:26 PM
Issues
1
Security Audit — snyk — wails