pp-ordertogo

Warn

Audited by Socket on May 11, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core ordering functionality matches the stated purpose and the installer appears same-publisher, but this skill gives an agent the ability to place real purchases and use imported browser session cookies. The optional arbitrary webhook sink further broadens data-flow risk beyond what a simple ordering helper needs.

Confidence: 86%Severity: 79%
Audit Metadata
Analyzed At
May 11, 2026, 12:44 PM
Package URL
pkg:socket/skills-sh/mvanhorn%2Fprinting-press-library%2Fpp-ordertogo%2F@aaf4c982a1c67ca414e625cc970dbf7da3f62797