pp-postman-explore

Warn

Audited by Socket on May 10, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core purpose is coherent with the capabilities, and the no-auth scope is proportionate, but the skill materially extends trust to external CLIs/MCP executables and includes optional arbitrary webhook delivery. That is more risk than a simple Postman directory helper needs, so this looks like a plausible but moderately risky agent skill rather than confirmed malicious behavior.

Confidence: 81%Severity: 62%
Audit Metadata
Analyzed At
May 10, 2026, 11:44 PM
Package URL
pkg:socket/skills-sh/mvanhorn%2Fprinting-press-library%2Fpp-postman-explore%2F@7f175b33b35409fa4218416e98fd53fb864d44de