pp-agentpool

Warn

Audited by Socket on Jul 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's behavior is broadly aligned with its stated purpose as a thin AgentPool wrapper, but the install trust story is weaker than ideal because it requires running a publisher-specific wrapper via `npx` or unpinned `go install @latest`. No clear credential theft or malicious data routing is disclosed, so this is better classified as medium supply-chain risk than malware.

Confidence: 80%Severity: 56%
Audit Metadata
Analyzed At
Jul 1, 2026, 06:08 PM
Package URL
pkg:socket/skills-sh/mvanhorn%2Fprinting-press-library%2Fpp-agentpool%2F@1f53afc0dd579f179f6e03d7e99dc0a6b6ff711ff2ed1d4666729078ba0d575d
Security Audit — socket — pp-agentpool