pp-pokeapi

Warn

Audited by Socket on May 9, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core Pokédex/query functionality is coherent, but the skill installs third-party executables from a different publisher than the listed author, uses unpinned @latest installs, and exposes arbitrary webhook output delivery plus optional remote feedback posting. These behaviors are not clearly necessary for an offline read-only Pokémon lookup skill, so the footprint is broader than its stated purpose.

Confidence: 82%Severity: 64%
Audit Metadata
Analyzed At
May 9, 2026, 06:26 PM
Package URL
pkg:socket/skills-sh/mvanhorn%2Fprinting-press-library%2Fpp-pokeapi%2F@0becc28e40621125124da41611ab769bfdafa65f