pp-google-play

Warn

Audited by Socket on Jun 23, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's stated Google Play scraping purpose broadly matches its capabilities and it does not request secrets, but it relies on external installs, uses unpinned latest code, includes arbitrary webhook delivery, and shows a publisher/package identity mismatch that weakens install trust. Risk is moderate rather than overtly malicious.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
Jun 23, 2026, 04:59 AM
Package URL
pkg:socket/skills-sh/mvanhorn%2Fprinting-press-library%2Fpp-google-play%2F@0e4220a6712f481cf79eef79a6cb879ae7795d815989b637a2feed4f85e90f74
Security Audit — socket — pp-google-play