agentphone

Warn

Audited by Socket on Apr 21, 2026

1 alert found:

Anomaly
AnomalyLOW
.mcp.json

This configuration itself is not implementing malware, but it does create a significant supply-chain execution pathway by using npx (-y) to download and run an external npm package at runtime. AGENTPHONE_BASE_URL and AGENTPHONE_API_KEY are passed to that dependency, implying authenticated network activity. Risk depends entirely on the trustworthiness and integrity of agentphone-mcp@0.2.0 and its transitive dependencies; mitigate by pre-installing from a locked/integrity-pinned source and reviewing the dependency code/behavior.

Confidence: 62%Severity: 62%
Audit Metadata
Analyzed At
Apr 21, 2026, 04:18 AM
Package URL
pkg:socket/skills-sh/agentphone-ai%2Fskills%2Fagentphone%2F@b6fb8055166716664c4673105889b24c04c5187b