pp-craigslist

Warn

Audited by Socket on May 8, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s Craigslist analysis purpose mostly matches its read-only capabilities, but it depends on external CLI/MCP installation and includes optional arbitrary webhook/output delivery that broadens data egress beyond what the core task needs. The main risk is supply-chain trust and outbound routing, not confirmed malicious behavior.

Confidence: 79%Severity: 61%
Audit Metadata
Analyzed At
May 8, 2026, 05:56 PM
Package URL
pkg:socket/skills-sh/mvanhorn%2Fprinting-press-library%2Fpp-craigslist%2F@9f0e48ae0a5a495311e348fa50a08020d39d83be