Apache Airflow MCP
Warn
Audited by Socket on Mar 28, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the functional purpose is plausible for an Airflow integration, but the installation and trust model are not coherent with the claimed Apache source. The skill is delivered through an unpinned, third-party, transitive install path (`agentskillexchange/skills`) rather than an Apache-operated source, so the main concern is supply-chain and inherited-permission risk rather than confirmed malicious behavior.
Confidence: 89%Severity: 78%
Audit Metadata