pp-agentpool
Warn
Audited by Socket on Jul 1, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill's behavior is broadly aligned with its stated purpose as a thin AgentPool wrapper, but the install trust story is weaker than ideal because it requires running a publisher-specific wrapper via `npx` or unpinned `go install @latest`. No clear credential theft or malicious data routing is disclosed, so this is better classified as medium supply-chain risk than malware.
Confidence: 80%Severity: 56%
Audit Metadata