pp-whoop

Warn

Audited by Socket on May 9, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated purpose is a WHOOP CLI wrapper, but it depends on an externally installed CLI whose official provenance is not established here, then feeds it WHOOP tokens and sensitive health/profile data. Arbitrary webhook delivery and MCP installation further broaden trust and exfiltration surface beyond a narrowly scoped API skill.

Confidence: 84%Severity: 84%
Audit Metadata
Analyzed At
May 9, 2026, 09:42 PM
Package URL
pkg:socket/skills-sh/mvanhorn%2Fprinting-press-library%2Fpp-whoop%2F@55edca658669975405b116b442fb5b7eddad1c6b