pp-openalex

Warn

Audited by Socket on May 11, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the stated read-only OpenAlex purpose mostly matches the commands, but the skill relies on runtime installation of a third-party CLI from a different publisher identity and includes arbitrary webhook delivery plus optional external feedback posting. This is not clearly malicious, yet its actual footprint is broader than a minimal API query skill and requires moderate trust in external binaries and outbound network paths.

Confidence: 79%Severity: 62%
Audit Metadata
Analyzed At
May 11, 2026, 03:52 PM
Package URL
pkg:socket/skills-sh/mvanhorn%2Fprinting-press-library%2Fpp-openalex%2F@f4e93885a43830bab0b0d0b7e82dd1188e2b0429