pp-company-goat

Warn

Audited by Socket on May 8, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

Mostly coherent as a read-only company-research skill, and its optional credentials broadly match the stated purpose. The main concerns are trust in externally installed binaries from a namespace that does not match the listed author, mutable @latest installs, and built-in arbitrary webhook delivery/optional feedback posting that create extra exfiltration paths. Overall this is better classified as suspicious-by-caution than malicious.

Confidence: 81%Severity: 61%
Audit Metadata
Analyzed At
May 8, 2026, 05:35 PM
Package URL
pkg:socket/skills-sh/mvanhorn%2Fprinting-press-library%2Fpp-company-goat%2F@6fd82f84c95b62c0f8a4586f5f770b76420dca6d