pp-dub

Warn

Audited by Socket on May 8, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The skill is broadly aligned with its stated Dub-management purpose, and the install sources are same-publisher and publicly verifiable rather than obviously deceptive. Risk comes from relying on external CLIs, mutable installer targets, optional arbitrary webhook delivery, and installation of an additional MCP server; these make it better classified as suspicious/medium-risk rather than benign, but not confirmed malicious.

Confidence: 83%Severity: 64%
Audit Metadata
Analyzed At
May 8, 2026, 05:59 PM
Package URL
pkg:socket/skills-sh/mvanhorn%2Fprinting-press-library%2Fpp-dub%2F@1edc2039753f95d1b529c8687b766a4408536664