waha
Warn
Audited by Socket on Mar 29, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill is mostly purpose-aligned as a WAHA client, with modest supply-chain risk, but it forwards a locally stored API key and all WhatsApp operations to an arbitrary user-configured WAHA endpoint, including non-official third-party infrastructure. The biggest concern is data-flow trust and autonomous external messaging, not hidden malware behavior.
Confidence: 88%Severity: 69%
Audit Metadata