pp-learn-disabled-example
Warn
Audited by Socket on Sep 2, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s stated purpose is mostly coherent, but it depends on not-fully-verified downstream CLI/MCP binaries, forwards tokens into that installed CLI, and permits output delivery to arbitrary webhook endpoints. This is not confirmed malware, but the install trust chain and flexible outbound data flows make the skill medium-high risk.
Confidence: 85%Severity: 78%
Audit Metadata