pp-ahrefs

Warn

Audited by Socket on May 8, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is mostly aligned with its stated Ahrefs read-only analysis purpose, but it relies on a non-Ahrefs third-party CLI/MCP wrapper, requires an Ahrefs API key, and supports arbitrary webhook delivery of results. The footprint is not fundamentally incompatible with the purpose, so this is not malware, but the install trust and data-routing model create medium security risk.

Confidence: 85%Severity: 58%
Audit Metadata
Analyzed At
May 8, 2026, 05:48 PM
Package URL
pkg:socket/skills-sh/mvanhorn%2Fprinting-press-library%2Fpp-ahrefs%2F@402cbb1f9b346d5255afc17bf501e88250c85afe