pp-twilio

Warn

Audited by Socket on May 11, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s stated Twilio analytics purpose partly matches its data-sync features, but its actual footprint is much broader: it installs non-Twilio third-party CLIs/MCP from a personal publisher, forwards Twilio credentials to that tooling, supports arbitrary webhook delivery, and exposes many destructive/admin Twilio operations unrelated to simple analytics. The behavior is not confirmed malicious, but the scope and trust model are disproportionate enough to warrant caution.

Confidence: 86%Severity: 76%
Audit Metadata
Analyzed At
May 11, 2026, 04:38 AM
Package URL
pkg:socket/skills-sh/mvanhorn%2Fprinting-press-library%2Fpp-twilio%2F@1b4d9dcd15bfb250b39248588fb53659b7b06029