pp-granola

Warn

Audited by Socket on May 13, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's purpose is plausible, but it relies on a non-verifiable external CLI that accesses local Granola caches, Keychain-managed token material, and optional refresh/API tokens. The arbitrary webhook delivery path and presence of state-changing commands further widen scope beyond a simple read-only meeting-analysis skill.

Confidence: 87%Severity: 84%
Audit Metadata
Analyzed At
May 13, 2026, 01:02 AM
Package URL
pkg:socket/skills-sh/mvanhorn%2Fprinting-press-library%2Fpp-granola%2F@f16075b8afc5cd43f0a9d3c8ff59db52b2dfe3ab