pp-janeapp
Warn
Audited by Socket on Jul 17, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill is not overt malware, and its installer provenance is same-org and publicly documented, but its actual footprint is broader and less coherent than the headline suggests. It handles Jane session cookies and stored credentials through a third-party personal-org CLI, includes arbitrary webhook export for potentially sensitive appointment data, and presents a notable purpose mismatch between 'book/manage' claims and read-only instructions. Medium risk overall, driven by credential handling, mutable installs, and outbound data-routing features rather than confirmed malicious behavior.
Confidence: 84%Severity: 62%
Audit Metadata