pp-fec
Warn
Audited by Socket on Aug 26, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The core FEC read-only querying purpose aligns with the documented CLI and same-org install sources, so this is not fundamentally malicious. Risk comes from broad helper features unrelated to basic FEC lookup—arbitrary webhook delivery, optional feedback endpoint posting, transitive MCP installation, and unconditional background learning/state writes—plus unpinned installer chains. Overall this looks coherent but over-scoped for a simple data-query skill.
Confidence: 87%Severity: 54%
Audit Metadata