pipa-huddle-beta

Warn

Audited by Socket on Aug 6, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's core behavior is mostly coherent with its stated purpose of launching a voice huddle, and the relay/OpenCode flows are proportionate for that use case. The main concerns are third-party data routing through voice.usepipa.com, persistence of session metadata, and a publisher-identity mismatch between the usepipa domain and the documented GitHub skill source, which weakens install trust enough to avoid a benign classification.

Confidence: 80%Severity: 58%
Audit Metadata
Analyzed At
Aug 6, 2026, 08:08 AM
Package URL
pkg:socket/skills-sh/lunchpaillola%2Fpipa-skills%2Fpipa-huddle-beta%2F@720ded55186539127366319776d80ba8fed4615c0aa2f1327fd267b0e9162cc6
Security Audit — socket — pipa-huddle-beta