Warn
Audited by Socket on Sep 15, 2026
1 alert found:
AnomalyAnomalyreferences/mcp-integration.md
LOWAnomalyLOW
references/mcp-integration.md
No direct malicious behavior is present in the supplied documentation. It does, however, recommend running unpinned third-party MCP packages and supplying them with highly sensitive credentials and broad email or marketing permissions. Pin and verify package versions and repository provenance, use least-privilege tokens and scoped permissions, protect configuration and token files, and review MCP server source code before deployment.
Confidence: 97%Severity: 62%
Audit Metadata