wix-headless-fast

Warn

Audited by Socket on Sep 16, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
references/restaurants/seed/seed-restaurants.mjs

No clear malicious code indicators (no eval/Function/dynamic execution, no suspicious domains beyond the hardcoded Wix API base, no local persistence). The module is a highly privileged automation tool: it executes `npx @wix/cli@latest` at runtime to obtain a bearer token and then performs authenticated, potentially destructive Wix API operations (installing apps, bulk creating/updating menus and images, and deleting sample menu entities; enabling ordering/reservations). Primary risk is supply-chain/version variability from using `@wix/cli@latest` plus operational impact from using bearer-token authenticated state-changing APIs; suppressed errors reduce auditability but do not themselves prove malice.

Confidence: 70%Severity: 55%
AnomalyLOW
entry/skill.md

SUSPICIOUS: the skill’s purpose and capabilities are mostly aligned for Wix onboarding, and data flows stay with Wix/offical tooling, but it asks the agent to download-execute an unpinned remote script and to install additional skills transitively. This looks more like medium supply-chain and trust-expansion risk than credential theft or confirmed malware.

Confidence: 89%Severity: 58%
Audit Metadata
Analyzed At
Sep 16, 2026, 03:25 PM
Package URL
pkg:socket/skills-sh/wix%2Fskills%2Fwix-headless-fast%2F@7c7e539d28ca4afb6663bf8d31ffd8667b98eef6112abf4ac21b6e38c132d940
Security Audit — socket — wix-headless-fast