wbso-logout

Warn

Audited by Socket on Sep 18, 2026

1 alert found:

Security
SecurityMEDIUM
scripts/wbso

The code appears to implement the advertised WBSO compliance CLI, but it has a high-impact command-injection vulnerability because parse_args evaluates command-line-derived text with eval. It also executes local configuration files and exposes potentially sensitive Claude/Codex prompts and Git data through compliance context output. No clear malware, credential-stealing backdoor, or obfuscated payload is present; the primary risks are unsafe shell evaluation, trust in mutable configuration, configurable credential destination, and sensitive-data disclosure.

Confidence: 98%Severity: 86%
Audit Metadata
Analyzed At
Sep 18, 2026, 06:13 AM
Package URL
pkg:socket/skills-sh/wbso-ai%2Fskill%2Fwbso-logout%2F@4f8d189665a760c5237233fa547833057ab6edc32c1ad0a67bcbe225b4386204
Security Audit — socket — wbso-logout