pp-braze

Warn

Audited by Socket on Sep 14, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core Braze-read capability is coherent with the stated purpose, and installs come from the same publisher rather than an unrelated third party. The main risk is trust in an external CLI installer plus unpinned `@latest` fallbacks, and the skill can route fetched data to arbitrary webhooks if asked. This is not confirmed malware, but it is more than low risk because it forwards Braze-accessed data through a black-box CLI and supports external delivery sinks.

Confidence: 86%Severity: 54%
Audit Metadata
Analyzed At
Sep 14, 2026, 11:47 AM
Package URL
pkg:socket/skills-sh/mvanhorn%2Fprinting-press-library%2Fpp-braze%2F@e268107579b913d85b2314985cfcd3bb924d75cfa07a34bee16d27a42063ddad
Security Audit — socket — pp-braze