pp-kie

Warn

Audited by Socket on Aug 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's purpose is coherent, but its actual trust model is not: a Kie.ai integration is mediated by a third-party Printing Press installer/CLI that receives the user's Kie token, and the CLI can route outputs to arbitrary webhooks. Public source and documented install steps reduce malware confidence, but the install chain, publisher mismatch, and credential forwarding make the skill high-risk relative to a direct official integration.

Confidence: 86%Severity: 74%
Audit Metadata
Analyzed At
Aug 28, 2026, 01:47 PM
Package URL
pkg:socket/skills-sh/mvanhorn%2Fprinting-press-library%2Fpp-kie%2F@9380d5f405078987443f4589da47eea1f08695b21a950b916fbedf6aa6fba9ea
Security Audit — socket — pp-kie