webmcp-sdk-skill
Warn
Audited by Socket on Apr 15, 2026
1 alert found:
SecuritySecurityrules/uni-app.md
MEDIUMSecurityMEDIUM
rules/uni-app.md
No strong evidence of overt malware in the provided fragment (it appears feature-oriented and un-obfuscated), but it intentionally creates a high-impact remote-control channel using a sessionId-backed remote controller and exposes side-effect actions (cart updates and payment-like operation) without any authorization/guardrails shown. The security posture therefore depends heavily on the authorization model for the sessionId and on whether the remote controller can be accessed by unauthorized parties; this should be treated as a significant security risk for production use.
Confidence: 56%Severity: 70%
Audit Metadata