pp-kit

Warn

Audited by Socket on May 20, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s purpose and capabilities mostly align with Kit automation, but its footprint is broader than a simple API helper because it requires third-party Printing Press binaries, uses unpinned installer paths, and supports arbitrary webhook delivery of command output. This is not confirmed malware, but it carries meaningful supply-chain and data-routing risk.

Confidence: 88%Severity: 61%
Audit Metadata
Analyzed At
May 20, 2026, 01:56 AM
Package URL
pkg:socket/skills-sh/mvanhorn%2Fprinting-press-library%2Fpp-kit%2F@070c7d62c7e25699e0c8f4939c3706eb41765c9d
Security Audit — socket — pp-kit