wbso-feedback

Warn

Audited by Socket on Sep 18, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/wbso

The code appears to be a legitimate compliance-service CLI rather than intentionally malicious malware. Its primary security concern is privacy exposure: the context command reads and emits Git history and local Claude/Codex user prompts, potentially disclosing sensitive information to downstream consumers. Sourcing configuration files creates arbitrary-code-execution risk if those files are tampered with. The eval-based argument parser is also unsafe design, although no definite exploit flow is established from the supplied code. No clear credential theft, persistence, destructive behavior, reverse shell, or cryptomining is present.

Confidence: 96%Severity: 62%
Audit Metadata
Analyzed At
Sep 18, 2026, 06:13 AM
Package URL
pkg:socket/skills-sh/wbso-ai%2Fskill%2Fwbso-feedback%2F@dafcf65ccbaf1075a4e6861a2c4f22d184bf1aa122f61c2cfb0729cc686d2d43
Security Audit — socket — wbso-feedback