whatsapp-web-js

Fail

Audited by Socket on Mar 11, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill content is largely coherent with its stated purpose of guiding development around WhatsApp Web JS automation. It describes legitimate usage patterns, authentication options, and operational considerations (rate limits, admin requirements, message/media handling). There are no explicit red flags for unverifiable binaries or external data exfiltration. Some minimal credential/data-flow considerations exist due to session persistence options, but these are inherent to the library’s authentic usage. Overall, the footprint is benign with respect to the stated purpose; monitor authentication storage and ensure any remote/session data remains under explicit user control.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 11, 2026, 09:12 AM
Package URL
pkg:socket/skills-sh/goncy%2Fskills%2Fwhatsapp-web-js%2F@cb846d185edd996f33858b6876ab32d4eccc2f6b