pp-braze
Warn
Audited by Socket on Sep 14, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The core Braze-read capability is coherent with the stated purpose, and installs come from the same publisher rather than an unrelated third party. The main risk is trust in an external CLI installer plus unpinned `@latest` fallbacks, and the skill can route fetched data to arbitrary webhooks if asked. This is not confirmed malware, but it is more than low risk because it forwards Braze-accessed data through a black-box CLI and supports external delivery sinks.
Confidence: 86%Severity: 54%
Audit Metadata