prepare-wordpress

Warn

Audited by Socket on May 10, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The main WordPress scaffolding behavior is coherent and mostly uses normal developer tooling, but the skill also performs transitive installation of multiple agent skills from unpinned GitHub sources, including a personal third-party repository and an archived/migrated repo reference. That extra trust chain is disproportionate to simple project setup and is the main risk driver, though there is no strong evidence of credential theft or overtly malicious behavior.

Confidence: 91%Severity: 76%
Audit Metadata
Analyzed At
May 10, 2026, 08:02 PM
Package URL
pkg:socket/skills-sh/soderlind%2Fskills%2Fprepare-wordpress%2F@993b3bebd2370c5709efde7fa570460df8176d64