building-mcp-servers
Warn
Audited by Socket on Jun 17, 2026
1 alert found:
AnomalyAnomalyreferences/schemas/overrides.yml
LOWAnomalyLOW
references/schemas/overrides.yml
No direct malicious logic is present in this fragment because it is purely a declarative schema. However, it enables configuration-driven indirection to runtime code execution (import hook scripts and script-based router functions) and configuration-driven response-to-record data mapping. The security impact is therefore moderate-to-high in environments where override config or referenced scripts can be tampered with, but malware cannot be confirmed from this snippet alone.
Confidence: 100%Severity: 60%
Audit Metadata