pp-myfitnesspal
Warn
Audited by Socket on May 9, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the core MyFitnessPal export/analysis purpose is coherent, and the install paths look broadly normal, but the skill relies on a high-trust external CLI that imports browser cookies and can forward sensitive nutrition data to arbitrary webhooks. The footprint is plausible for the task yet broader than necessary, so this is best classified as medium-risk rather than benign.
Confidence: 82%Severity: 63%
Audit Metadata