pp-vagaro

Warn

Audited by Socket on Aug 23, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The skill is broadly aligned with its stated Vagaro discovery and rebooking purpose, and the install sources are same-org and publicly traceable. Main concerns are medium-risk supply-chain hygiene (`@latest`/`npx -y`), transitive skill installation via a separate CLI, browser-session import for auth, and optional arbitrary webhook delivery that can exfiltrate sensitive output. Overall this is suspicious from a security-hardening perspective but not confirmed malicious.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
Aug 23, 2026, 04:51 PM
Package URL
pkg:socket/skills-sh/mvanhorn%2Fprinting-press-library%2Fpp-vagaro%2F@163ddb9d33f3a2a7e2e4d90eb9558f7c14b8dac5eef830a380ee3a42fc5a50cf
Security Audit — socket — pp-vagaro