pp-recipe-goat

Warn

Audited by Socket on May 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core recipe/USDA lookup purpose is coherent and the credential scope is proportionate, but install trust is weakened by publisher mismatch and unpinned external CLI/MCP installation. The optional webhook delivery and transitive MCP install raise meaningful security risk, though there is no clear evidence of credential theft or behavior fundamentally incompatible with the stated purpose.

Confidence: 82%Severity: 57%
Audit Metadata
Analyzed At
May 15, 2026, 05:52 PM
Package URL
pkg:socket/skills-sh/mvanhorn%2Fprinting-press-library%2Fpp-recipe-goat%2F@f49aa7b2a741154885586c134d8920ab9694fb75
Security Audit — socket — pp-recipe-goat