fortytwo-mcp
Warn
Audited by Socket on Sep 15, 2026
1 alert found:
AnomalyAnomalyscripts/fortytwo_query.py
LOWAnomalyLOW
scripts/fortytwo_query.py
The code is primarily a paid API/MCP client and does not show clear malware, credential theft, or destructive behavior. It does expose a high-impact payment flow: any compromised or malicious gateway response could cause the configured private key to authorize payment to an attacker-selected recipient and amount, subject to the token authorization semantics. The lack of explicit confirmation and insecure /tmp session storage are significant security weaknesses. The code as pasted is also syntactically incomplete at the final main( call.
Confidence: 96%Severity: 68%
Audit Metadata