pp-klaviyo

Warn

Audited by Socket on May 8, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s Klaviyo-focused capabilities mostly fit its stated purpose, but its trust boundary is weak. It installs and relies on third-party binaries from a different publisher identity, can route results to arbitrary webhook endpoints, and enables non-interactive real-world actions like sending campaigns and messages. This is not confirmed malware, but it is high-risk for credential exposure, exfiltration, and unintended account actions.

Confidence: 85%Severity: 72%
Audit Metadata
Analyzed At
May 8, 2026, 06:05 PM
Package URL
pkg:socket/skills-sh/mvanhorn%2Fprinting-press-library%2Fpp-klaviyo%2F@b40c9ac29d1fc817540d5577e29480b5fb59e260