pp-recipe-goat

Warn

Audited by Socket on May 8, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the stated purpose is coherent and mostly read-only, but the skill expands trust to external binaries installed via npx/go without supplied verification evidence, supports arbitrary webhook delivery of output, and optionally installs an MCP server that increases agent-side trust. Credentials requested are proportionate, so this is not clearly malicious, but the install and data-delivery footprint is broader than a simple recipe lookup helper.

Confidence: 82%Severity: 60%
Audit Metadata
Analyzed At
May 8, 2026, 04:56 PM
Package URL
pkg:socket/skills-sh/mvanhorn%2Fprinting-press-library%2Fpp-recipe-goat%2F@5c7b2d088375903b0737055d9a7e7bf4c2584dec