pp-edgar

Warn

Audited by Socket on May 17, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the stated EDGAR research purpose is mostly coherent, but the skill depends on externally installed binaries with unclear publisher linkage and permits arbitrary outbound webhook delivery. This looks more like elevated supply-chain and data-routing risk than confirmed malware.

Confidence: 82%Severity: 62%
Audit Metadata
Analyzed At
May 17, 2026, 11:28 PM
Package URL
pkg:socket/skills-sh/mvanhorn%2Fprinting-press-library%2Fpp-edgar%2F@314d858aee6acc67df3a686420109b4265360cf7
Security Audit — socket — pp-edgar