pp-redfin

Warn

Audited by Socket on May 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core purpose is coherent for a Redfin analysis skill, and there is no direct credential harvesting or obvious malicious code. However, the skill depends on third-party executables installed at runtime from a different publisher namespace than the skill author, uses mutable installers, adds an MCP server, and exposes arbitrary webhook delivery. This is better classified as medium-risk supply-chain and outbound-data exposure rather than confirmed malware.

Confidence: 82%Severity: 56%
Audit Metadata
Analyzed At
May 16, 2026, 03:21 AM
Package URL
pkg:socket/skills-sh/mvanhorn%2Fprinting-press-library%2Fpp-redfin%2F@74b36d17443a10470376732885c9058f3d2baaf5
Security Audit — socket — pp-redfin