pp-squarespace

Warn

Audited by Socket on Jun 14, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s broad commerce mutation capabilities and arbitrary webhook output are not fully aligned with its read-focused description, and it forwards sensitive tokens/session cookies into an external CLI. Install sources are not overtly malicious, but the overall footprint is high-trust and wider than the stated purpose.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 14, 2026, 09:12 PM
Package URL
pkg:socket/skills-sh/mvanhorn%2Fprinting-press-library%2Fpp-squarespace%2F@36eaea52c77b56bc644476e768ab830c9e42a5fa23192b95fd436c0b29424633
Security Audit — socket — pp-squarespace