pp-wikipedia

Warn

Audited by Socket on May 8, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core Wikipedia purpose is mostly coherent, but the trust chain is blurred by third-party installer sources under a different identity, and the skill adds disproportionate capabilities such as arbitrary webhook delivery and MCP installation. Not confirmed malware, but broader and riskier than a simple read-only Wikipedia helper needs to be.

Confidence: 84%Severity: 67%
Audit Metadata
Analyzed At
May 8, 2026, 05:58 PM
Package URL
pkg:socket/skills-sh/mvanhorn%2Fprinting-press-library%2Fpp-wikipedia%2F@60e36eaf5d9d507a4c4633f927c8c7ed58c04034