waha

Warn

Audited by Socket on Mar 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is mostly purpose-aligned as a WAHA client, with modest supply-chain risk, but it forwards a locally stored API key and all WhatsApp operations to an arbitrary user-configured WAHA endpoint, including non-official third-party infrastructure. The biggest concern is data-flow trust and autonomous external messaging, not hidden malware behavior.

Confidence: 88%Severity: 69%
Audit Metadata
Analyzed At
Mar 29, 2026, 03:32 AM
Package URL
pkg:socket/skills-sh/idjoo%2Fskills%2Fwaha%2F@5e79f3fd4142831cd32e000e2f73a24ef6f5766f