pp-xai

Warn

Audited by Socket on Jul 8, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's purpose mostly matches its capabilities, but it requires a non-official third-party CLI to install and handle xAI credentials, uses unpinned install paths, and supports arbitrary webhook output delivery. This looks more like a high-risk third-party wrapper than malware, but the trust and credential-routing model is disproportionate for an xAI-branded access skill.

Confidence: 87%Severity: 81%
Audit Metadata
Analyzed At
Jul 8, 2026, 08:14 PM
Package URL
pkg:socket/skills-sh/mvanhorn%2Fprinting-press-library%2Fpp-xai%2F@bc981f5baf1180140bd4c0ce518359eefc01d8897adeccfbb338d151e2970802
Security Audit — socket — pp-xai