pp-coingecko

Warn

Audited by Socket on May 8, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core purpose is coherent for read-only CoinGecko access, but the skill relies on external CLIs, unpinned installs, optional arbitrary webhook delivery, and MCP registration. These behaviors are not clearly malicious, yet they broaden trust and data-flow scope beyond a simple API query skill.

Confidence: 79%Severity: 56%
Audit Metadata
Analyzed At
May 8, 2026, 05:35 PM
Package URL
pkg:socket/skills-sh/mvanhorn%2Fprinting-press-library%2Fpp-coingecko%2F@f93afbbdb00f887a400a8ac33e0dd427e3f2b9d8