pp-substack
Warn
Audited by Socket on May 9, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill is coherent as a Substack automation wrapper, but it expands trust to external CLIs/MCP components, uses browser-cookie account access, enables autonomous public posting, and adds an arbitrary webhook sink that can exfiltrate output. This is high operational risk even without clear evidence of confirmed malware.
Confidence: 86%Severity: 78%
Audit Metadata