pp-fathom

Warn

Audited by Socket on May 27, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core purpose is coherent for a Fathom analytics skill, and the required Fathom API key is proportionate, but the skill’s real footprint depends on trusting external CLIs and includes optional arbitrary webhook delivery for synced meeting data. That combination makes it higher risk than a normal documentation-only skill, mainly due to supply-chain trust and data-exfiltration potential rather than confirmed malicious intent.

Confidence: 81%Severity: 58%
Audit Metadata
Analyzed At
May 27, 2026, 02:17 AM
Package URL
pkg:socket/skills-sh/mvanhorn%2Fprinting-press-library%2Fpp-fathom%2F@37a13a162bee00ff8e1e793127bf9e6ade1e73d8
Security Audit — socket — pp-fathom