pp-judge-me

Warn

Audited by Socket on Jun 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s core purpose is coherent, but it expands trust to third-party CLI/MCP binaries, forwards API credentials to them, and includes arbitrary webhook output delivery that can exfiltrate fetched data. The main concern is install/provenance ambiguity and broad outbound sinks, not confirmed malware.

Confidence: 81%Severity: 63%
Audit Metadata
Analyzed At
Jun 28, 2026, 04:22 PM
Package URL
pkg:socket/skills-sh/mvanhorn%2Fprinting-press-library%2Fpp-judge-me%2F@1b805bc71e0edb9776c8e9770c575a117354ef01edf71e8a87f92e81dd994d4a
Security Audit — socket — pp-judge-me