pp-openrouter

Warn

Audited by Socket on May 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is broadly aligned with OpenRouter introspection, but it relies on a separately installed third-party CLI from a different publisher identity than the skill author, uses unpinned install paths, forwards API credentials to that binary, and supports arbitrary webhook delivery. This looks more like a risky external-tool wrapper than confirmed malware.

Confidence: 84%Severity: 66%
Audit Metadata
Analyzed At
May 15, 2026, 06:02 PM
Package URL
pkg:socket/skills-sh/mvanhorn%2Fprinting-press-library%2Fpp-openrouter%2F@b0f2b0c68f37c8d309e7e8869549abf43fea3a6b
Security Audit — socket — pp-openrouter