waniwani-sdk

Warn

Audited by Socket on Oct 7, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/tunnel.md

The fragment is a legitimate tunneling playbook and contains no evident malware or intentional data theft. Its main security risk is operational: it publicly exposes a local development MCP server and may execute project-defined commands. Users should verify the dev server’s authentication and authorization, avoid exposing sensitive tools or data, and independently validate privileged installation commands before running them.

Confidence: 98%Severity: 57%
Audit Metadata
Analyzed At
Oct 7, 2026, 12:14 PM
Package URL
pkg:socket/skills-sh/waniwani-ai%2Fsdk%2Fwaniwani-sdk%2F@a4c2c2bdccf447773608875f7cc233173c0b885256ed138ff8da49b66582dc93