ghost-theme

Warn

Audited by Socket on Apr 15, 2026

1 alert found:

Anomaly
AnomalyLOW
base-template/.mcp.json

This snippet does not itself implement malicious behavior; it configures an MCP server that will execute a third-party npm package via npx (runtime fetch-and-run supply-chain risk) and connect to a Ghost CMS instance in admin mode. The inclusion of an admin API key variable and explicit admin mode meaningfully increases potential impact if the executed package or its dependencies are compromised. Review/lock the exact @damusix/ghost-mcp version and transitive dependency tree, and restrict/secure the admin credentials and execution environment. Overall, the security risk is moderate-to-elevated due to supply-chain execution with admin-level capability, while malware indicators cannot be confirmed from this fragment alone.

Confidence: 62%Severity: 62%
Audit Metadata
Analyzed At
Apr 15, 2026, 09:27 AM
Package URL
pkg:socket/skills-sh/damusix%2Fskills%2Fghost-theme%2F@bb19b7de121549f2c9c1f3ceaef5a7ca30b8c2dc