wix-replatform

Warn

Audited by Socket on Aug 27, 2026

2 alerts found:

AnomalySecurity
AnomalyLOW
resources/rp-setup-discovery/SKILL.md

SUSPICIOUS. The skill’s main capabilities are consistent with Wix setup planning and mostly stay local, but it includes an optional third-party ngrok install plus credential forwarding for media reachability. Because that external CLI is proprietary, unpinned, and receives a token, the skill carries medium security risk even though the overall purpose-capability alignment is otherwise coherent.

Confidence: 86%Severity: 56%
SecurityMEDIUM
resources/rp-source-wordpress/plugins/back-in-stock-notifier-for-woocommerce.json

The fragment is a readable integration manifest for importing WooCommerce back-in-stock subscriber data. It does not contain executable malware or an obfuscated payload, but it specifies a path for broad retrieval and downstream transfer of sensitive subscriber information and documents a persistent record-creation endpoint. Use requires explicit store authorization, strict access control, data minimization, and validation of the target importer. The configuration presents a significant privacy and data-handling risk if deployed without those controls.

Confidence: 96%Severity: 72%
Audit Metadata
Analyzed At
Aug 27, 2026, 03:40 PM
Package URL
pkg:socket/skills-sh/wix%2Fskills%2Fwix-replatform%2F@cfe906e94f764dc17521bbc65c3eb59127e37af4e87fec9df1426be263719598
Security Audit — socket — wix-replatform