wayai

Warn

Audited by Socket on May 12, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s core capabilities mostly match its stated purpose as a WayAI workspace/CLI guide, and the credential scope is broadly proportionate to a SaaS hub-management tool. The main concerns are supply-chain and trust-chain related: it instructs the agent to globally install an external CLI, use unpinned latest versions, and install another skill transitively via `npx skills add`. No clear credential exfiltration or deceptive third-party routing is shown, so this is not malicious, but it carries medium security risk.

Confidence: 80%Severity: 58%
Audit Metadata
Analyzed At
May 12, 2026, 04:59 PM
Package URL
pkg:socket/skills-sh/wayai-pro%2Fwayai-skill%2Fwayai%2F@3a60975b1459f6ac7e6ac8b7d8db301bff58ebd7