pp-espn

Warn

Audited by Socket on May 9, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the main sports-data purpose broadly matches the CLI, but the skill's footprint is wider than necessary. Unpinned external installs are a medium supply-chain risk, and the generic webhook delivery, optional upstream feedback POSTs, and overrideable base URL create disproportionate outbound data paths for an ESPN lookup skill.

Confidence: 82%Severity: 68%
Audit Metadata
Analyzed At
May 9, 2026, 05:01 PM
Package URL
pkg:socket/skills-sh/mvanhorn%2Fprinting-press-library%2Fpp-espn%2F@6ed4fe72f74f30d4dab1ecd3cbda978723b2dec9