pp-pagliacci
Warn
Audited by Socket on May 8, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The overall purpose is coherent for a pizza-ordering skill, but the footprint is broader than a simple menu helper: it requires installing unverified external CLI/MCP components, reads browser auth cookies, can perform financially meaningful account/order actions, and supports arbitrary webhook delivery of data. The behavior fits the stated purpose, yet the install trust and data-routing model make it higher-risk than a typical consumer ordering skill.
Confidence: 82%Severity: 76%
Audit Metadata