pp-xai
Warn
Audited by Socket on Jul 8, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill's purpose mostly matches its capabilities, but it requires a non-official third-party CLI to install and handle xAI credentials, uses unpinned install paths, and supports arbitrary webhook output delivery. This looks more like a high-risk third-party wrapper than malware, but the trust and credential-routing model is disproportionate for an xAI-branded access skill.
Confidence: 87%Severity: 81%
Audit Metadata