pp-google-photos

Warn

Audited by Socket on May 8, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is broadly aligned with Google Photos management, but it depends on externally installed CLI/MCP binaries, includes a transitive MCP install step, and supports arbitrary webhook output delivery that can exfiltrate results. Credentials and Google API access are proportionate to purpose, so this is not confirmed malicious, but the install trust and data-routing footprint make it medium risk.

Confidence: 80%Severity: 64%
Audit Metadata
Analyzed At
May 8, 2026, 06:04 PM
Package URL
pkg:socket/skills-sh/mvanhorn%2Fprinting-press-library%2Fpp-google-photos%2F@1bec93b174b4d9ff1589d386e33018ca34fd4fbe