pp-janeapp

Warn

Audited by Socket on Jul 17, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is not overt malware, and its installer provenance is same-org and publicly documented, but its actual footprint is broader and less coherent than the headline suggests. It handles Jane session cookies and stored credentials through a third-party personal-org CLI, includes arbitrary webhook export for potentially sensitive appointment data, and presents a notable purpose mismatch between 'book/manage' claims and read-only instructions. Medium risk overall, driven by credential handling, mutable installs, and outbound data-routing features rather than confirmed malicious behavior.

Confidence: 84%Severity: 62%
Audit Metadata
Analyzed At
Jul 17, 2026, 06:48 PM
Package URL
pkg:socket/skills-sh/mvanhorn%2Fprinting-press-library%2Fpp-janeapp%2F@297f102c5571454d6828c3b64b186ce436c1380011cad59b3d729f82b0d1d0b8
Security Audit — socket — pp-janeapp