pp-fedex

Warn

Audited by Socket on May 8, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the shipping-related capabilities mostly fit the stated purpose, but the skill relies on third-party executables from a different publisher namespace, uses unpinned install paths, supports transitive MCP installation, and allows arbitrary webhook delivery of shipment/output data. The footprint is broader than a simple FedEx API guide and warrants caution, especially around credential handling and outbound data routing.

Confidence: 85%Severity: 78%
Audit Metadata
Analyzed At
May 8, 2026, 06:02 PM
Package URL
pkg:socket/skills-sh/mvanhorn%2Fprinting-press-library%2Fpp-fedex%2F@63336e179b1a7cde43ff47da16d686b5b84dc2ba