pp-company-goat
Warn
Audited by Socket on May 8, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
Mostly coherent as a read-only company-research skill, and its optional credentials broadly match the stated purpose. The main concerns are trust in externally installed binaries from a namespace that does not match the listed author, mutable @latest installs, and built-in arbitrary webhook delivery/optional feedback posting that create extra exfiltration paths. Overall this is better classified as suspicious-by-caution than malicious.
Confidence: 81%Severity: 61%
Audit Metadata