pp-catasto

Warn

Audited by Socket on Aug 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s core read-only cadastral lookup behavior is coherent, and the documented npm/Go install paths appear tied to the same Printing Press project rather than a random third party. However, it still requires trusting an external binary, uses an unpinned Go install fallback, supports arbitrary webhook output delivery, and includes MCP registration that extends trust to another executable. These are moderate security risks, but there is no clear evidence of credential harvesting or overtly malicious behavior.

Confidence: 87%Severity: 52%
Audit Metadata
Analyzed At
Aug 29, 2026, 07:14 AM
Package URL
pkg:socket/skills-sh/mvanhorn%2Fprinting-press-library%2Fpp-catasto%2F@3c652d58427c0cceb8c6d7aa3765f410583325a2ae71f299a7b1d27888a1446f
Security Audit — socket — pp-catasto