mcp-sdk-audit

Warn

Audited by Socket on Aug 13, 2026

1 alert found:

Anomaly
AnomalyLOW
probe.mjs

No direct evidence of embedded malware (no eval/Function, no network exfiltration, no credential theft/persistence) in this snippet. However, it contains a high-impact operational risk: it spawns and runs a Node entrypoint from a caller-provided repository path with full environment passthrough, effectively turning it into an execution harness if `repo` is not fully trusted. Additional robustness risk exists from unguarded JSON.parse of untrusted child stdout.

Confidence: 70%Severity: 55%
Audit Metadata
Analyzed At
Aug 13, 2026, 06:24 AM
Package URL
pkg:socket/skills-sh/awdr74100%2Ffigwright%2Fmcp-sdk-audit%2F@62da14da424edec5dfda116bc235b21497e82e4a4d186ddc2765b3a94437f495
Security Audit — socket — mcp-sdk-audit