wbso

Warn

Audited by Socket on Sep 18, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/wbso

The code appears to be a legitimate compliance-service CLI rather than intentionally malicious malware. Its primary security concern is privacy exposure: the context command reads and emits Git history and local Claude/Codex user prompts, potentially disclosing sensitive information to downstream consumers. Sourcing configuration files creates arbitrary-code-execution risk if those files are tampered with. The eval-based argument parser is also unsafe design, although no definite exploit flow is established from the supplied code. No clear credential theft, persistence, destructive behavior, reverse shell, or cryptomining is present.

Confidence: 96%Severity: 62%
Audit Metadata
Analyzed At
Sep 18, 2026, 06:13 AM
Package URL
pkg:socket/skills-sh/wbso-ai%2Fskill%2Fwbso%2F@df3b555c35bb3b6180932d5d620d06a3faaaa0f1a4b035f2f039f8b83967e4b7
Security Audit — socket — wbso