kvcore-mcp-cli

Fail

Audited by Snyk on Jun 16, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E005: Suspicious download URL detected in skill instructions.

  • Suspicious download URL detected (high risk: 0.70). The link points to an unvetted GitHub repository owned by an unfamiliar account and the skill is installed via npx (which executes remote code), so although GitHub is a common code host this is an untrusted source that could be used to distribute malicious scripts.

Issues (1)

E005
CRITICAL

Suspicious download URL detected in skill instructions.

Audit Metadata
Risk Level
CRITICAL
Analyzed
Jun 16, 2026, 01:03 AM
Issues
1
Security Audit — snyk — kvcore-mcp-cli