pp-fec

Warn

Audited by Socket on Aug 26, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core FEC read-only querying purpose aligns with the documented CLI and same-org install sources, so this is not fundamentally malicious. Risk comes from broad helper features unrelated to basic FEC lookup—arbitrary webhook delivery, optional feedback endpoint posting, transitive MCP installation, and unconditional background learning/state writes—plus unpinned installer chains. Overall this looks coherent but over-scoped for a simple data-query skill.

Confidence: 87%Severity: 54%
Audit Metadata
Analyzed At
Aug 26, 2026, 11:41 PM
Package URL
pkg:socket/skills-sh/mvanhorn%2Fprinting-press-library%2Fpp-fec%2F@9aa6f86446aa5f067fada51a82d360308138787fd5bcb18e5877301214bd8832
Security Audit — socket — pp-fec