pp-ordertogo
Warn
Audited by Socket on May 11, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The core ordering functionality matches the stated purpose and the installer appears same-publisher, but this skill gives an agent the ability to place real purchases and use imported browser session cookies. The optional arbitrary webhook sink further broadens data-flow risk beyond what a simple ordering helper needs.
Confidence: 86%Severity: 79%
Audit Metadata