wix-replatform
Audited by Socket on Aug 27, 2026
2 alerts found:
AnomalySecuritySUSPICIOUS. The skill’s main capabilities are consistent with Wix setup planning and mostly stay local, but it includes an optional third-party ngrok install plus credential forwarding for media reachability. Because that external CLI is proprietary, unpinned, and receives a token, the skill carries medium security risk even though the overall purpose-capability alignment is otherwise coherent.
The fragment is a readable integration manifest for importing WooCommerce back-in-stock subscriber data. It does not contain executable malware or an obfuscated payload, but it specifies a path for broad retrieval and downstream transfer of sensitive subscriber information and documents a persistent record-creation endpoint. Use requires explicit store authorization, strict access control, data minimization, and validation of the target importer. The configuration presents a significant privacy and data-handling risk if deployed without those controls.