webmcp-sdk-skill

Warn

Audited by Socket on Apr 15, 2026

1 alert found:

Security
SecurityMEDIUM
rules/uni-app.md

No strong evidence of overt malware in the provided fragment (it appears feature-oriented and un-obfuscated), but it intentionally creates a high-impact remote-control channel using a sessionId-backed remote controller and exposes side-effect actions (cart updates and payment-like operation) without any authorization/guardrails shown. The security posture therefore depends heavily on the authorization model for the sessionId and on whether the remote controller can be accessed by unauthorized parties; this should be treated as a significant security risk for production use.

Confidence: 56%Severity: 70%
Audit Metadata
Analyzed At
Apr 15, 2026, 09:30 AM
Package URL
pkg:socket/skills-sh/opentiny%2Fagent-skills%2Fwebmcp-sdk-skill%2F@4cfad0e83d8db23c59bbad8fbd5558547d065726