mcp-server-12306

Fail

Audited by Snyk on May 18, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E005: Suspicious download URL detected in skill instructions.

  • Suspicious download URL detected (high risk: 0.70). This set includes an unknown GitHub repo (git clone/pipx instructions) and a Docker image reference under an unverified username (drfccv), plus a short unfamiliar domain (ara.so) and instructions to run code locally (http://localhost:8000/mcp); while GitHub and localhost can be legitimate, cloning/pulling and executing code or containers from untrusted/low‑reputation sources is a common malware vector, so inspect the repo, image, and domain before running.

Issues (1)

E005
CRITICAL

Suspicious download URL detected in skill instructions.

Audit Metadata
Risk Level
CRITICAL
Analyzed
May 18, 2026, 08:35 PM
Issues
1
Security Audit — snyk — mcp-server-12306