wbso-auth

Warn

Audited by Socket on Sep 18, 2026

1 alert found:

Security
SecurityMEDIUM
scripts/wbso

The code appears to implement the advertised WBSO compliance CLI, but it has a high-impact command-injection vulnerability because parse_args evaluates command-line-derived text with eval. It also executes local configuration files and exposes potentially sensitive Claude/Codex prompts and Git data through compliance context output. No clear malware, credential-stealing backdoor, or obfuscated payload is present; the primary risks are unsafe shell evaluation, trust in mutable configuration, configurable credential destination, and sensitive-data disclosure.

Confidence: 98%Severity: 86%
Audit Metadata
Analyzed At
Sep 18, 2026, 06:13 AM
Package URL
pkg:socket/skills-sh/wbso-ai%2Fskill%2Fwbso-auth%2F@e6d595f956abd85327e1ec9f8f166398ddf94ce672aa7d753e46a21d4c4c61be
Security Audit — socket — wbso-auth