bluebubbles

Fail

Audited by Socket on Mar 8, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill appears to be a cohesive plugin module for BlueBubbles with webhook, REST, and extension-based architecture aligned to the stated purpose. Key risk areas center on credential handling (password in config), webhook data validation, and ensuring all REST calls use trusted endpoints with proper TLS. No obvious unverifiable binaries or autonomous real-world actions are present. The data flows are consistent with a legitimate messaging plugin, but credential exposure and external data routing require careful controls. Overall, the footprint is plausible for its purpose but warrants tightened secret management, explicit TLS enforcement, and rigorous input validation to achieve a benign security posture.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 8, 2026, 12:25 AM
Package URL
pkg:socket/skills-sh/malue-ai%2Fdazee-small%2Fbluebubbles%2F@5fb8197be5df895de4d125a082c680a2a822a06f