pp-kit
Warn
Audited by Socket on May 20, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill’s purpose and capabilities mostly align with Kit automation, but its footprint is broader than a simple API helper because it requires third-party Printing Press binaries, uses unpinned installer paths, and supports arbitrary webhook delivery of command output. This is not confirmed malware, but it carries meaningful supply-chain and data-routing risk.
Confidence: 88%Severity: 61%
Audit Metadata