Apache Airflow MCP

Warn

Audited by Socket on Mar 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the functional purpose is plausible for an Airflow integration, but the installation and trust model are not coherent with the claimed Apache source. The skill is delivered through an unpinned, third-party, transitive install path (`agentskillexchange/skills`) rather than an Apache-operated source, so the main concern is supply-chain and inherited-permission risk rather than confirmed malicious behavior.

Confidence: 89%Severity: 78%
Audit Metadata
Analyzed At
Mar 28, 2026, 05:51 PM
Package URL
pkg:socket/skills-sh/agentskillexchange%2Fskills%2Fapache-airflow-mcp%2F@97f03497c7d8f51023e9a6e9e95e2a114373ed31