pp-granola
Warn
Audited by Socket on May 13, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill's purpose is plausible, but it relies on a non-verifiable external CLI that accesses local Granola caches, Keychain-managed token material, and optional refresh/API tokens. The arbitrary webhook delivery path and presence of state-changing commands further widen scope beyond a simple read-only meeting-analysis skill.
Confidence: 87%Severity: 84%
Audit Metadata