pp-techmeme

Warn

Audited by Socket on May 12, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core read-only Techmeme purpose is coherent, but the trust story is weakened by external installer execution, mutable @latest installs, unclear publisher-to-package relationship, and arbitrary webhook export. No clear credential harvesting or covert behavior is present, so this is not confirmed malware, but it carries medium supply-chain and outbound-data risk.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
May 12, 2026, 02:41 AM
Package URL
pkg:socket/skills-sh/mvanhorn%2Fprinting-press-library%2Fpp-techmeme%2F@0782c339d8fd242c6ffd56fe8459df75560b05e2