pagr

Warn

Audited by Socket on May 20, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core Pagr publishing capability is coherent, but the skill includes a plaintext API key in the remote MCP URL and instructs users to route actions through that endpoint, which is a serious credential-handling and data-flow issue. It also bootstraps additional agent skill/MCP components via unpinned runtime package execution, increasing trust-chain risk beyond simple HTML publishing.

Confidence: 91%Severity: 78%
Audit Metadata
Analyzed At
May 20, 2026, 12:39 PM
Package URL
pkg:socket/skills-sh/getpagr%2Fskills%2Fpagr%2F@b880bc1fc20c3711eb7f8999b26087e9ec60ba1f
Security Audit — socket — pagr