pp-ankiweb
Warn
Audited by Socket on Jun 15, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The core purpose and AnkiWeb-focused capabilities are mostly coherent, and the install sources appear same-publisher and proportionate. The main risk is that the skill delegates trust to an external CLI and includes arbitrary webhook delivery of outputs, which expands data-flow scope beyond normal AnkiWeb querying. No strong evidence of malware or hidden credential theft, but the external binary plus exfiltration-capable output sink make it medium risk.
Confidence: 100%Severity: 60%
Audit Metadata