wp-trac-timeline

Fail

Audited by Socket on Feb 28, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill metadata itself is reasonable for its purpose but grants a powerful sink: executing a local PHP script with user-derived arguments. Without the timeline.php source, there is meaningful risk of credential exposure, data exfiltration, or arbitrary command execution. Treat this package as a medium security risk until timeline.php is reviewed and validated. If the script is verified to be well-behaved (restricted network targets, safe auth, no arbitrary filesystem access), the risk is acceptable for the stated function.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 28, 2026, 12:19 AM
Package URL
pkg:socket/skills-sh/sirreal%2Fagent-skills%2Fwp-trac-timeline%2F@984674fbede57c8b9ff24ed596187889f0ec05d9