MCP Generator
Warn
Audited by Socket on Jul 22, 2026
1 alert found:
SecuritySecuritytemplates/server.ts.hbs
MEDIUMSecurityMEDIUM
templates/server.ts.hbs
The module primarily wraps an external `gitnexus` CLI, but it does so using `execSync` with a shell-interpreted command string built from untrusted MCP inputs. This creates a command-injection risk that could allow arbitrary command execution under the server’s privileges. While direct malware behavior is not evident from this snippet, the dominant security issue is the unsafe process execution and the return of raw command output/error details to the caller.
Confidence: 78%Severity: 78%
Audit Metadata