kagi-session2api-mcp-server

Warn

Audited by Socket on May 17, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is coherent as a Kagi search/summarization integration, and its install path is relatively normal, but its central mechanism is using full-account Kagi session tokens to bypass the official paid API. That makes credential scope disproportionate, data flow riskier than a normal API client, and the overall skill higher risk than a standard MCP integration.

Confidence: 84%Severity: 69%
Audit Metadata
Analyzed At
May 17, 2026, 07:28 AM
Package URL
pkg:socket/skills-sh/Aradotso%2Fmcp-skills%2Fkagi-session2api-mcp-server%2F@484a1cca83b4b0fa9a3b1956fb780c3d9c902f99
Security Audit — socket — kagi-session2api-mcp-server