who-blue-books

Fail

Audited by Socket on Mar 7, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill is generally coherent with its stated educational purpose of interfacing with WHO Blue Book content via a dedicated CLI. The primary security concerns center on installation provenance and credential management for the who-api-client (unverified install sources and subscription handling). Data flow appears to be within expected boundaries for a knowledge-aid tool, with no evident exfiltration or autonomous real-world actions. Given the unverifiable install path and credential dependency, the risk is better classified as suspicious rather than benign, pending clarification on trusted installation sources, signing, and explicit credential-handling practices.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 7, 2026, 05:13 PM
Package URL
pkg:socket/skills-sh/tbedau%2Fwho-blue-books-skills%2Fwho-blue-books%2F@4783a15249d872b5c6629887ba26cc91c19f26d9