gate-mcp-codex-installer

Warn

Audited by Socket on Apr 2, 2026

2 alerts found:

AnomalySecurity
AnomalyLOW
scripts/mcp-fragments/codex/gate-main-gate-mcp-placeholder.toml

Best assessment: the snippet is not evidence of overt malware, but it is a high-impact security hygiene issue because it hardcodes API credentials in configuration and passes them into an external process via environment variables. Ensure real secrets are not committed, use secret managers/CI variables, and verify the `gate-mcp` binary provenance and logging behavior. Review rotatability of any potentially exposed credentials.

Confidence: 62%Severity: 55%
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated purpose matches an installer, but the footprint is broader than necessary: it executes installer scripts, installs all skills by default, and routes future MCP traffic and credentials through gatemcp.ai endpoints. Same-org GitHub references reduce concern somewhat, but the transitive skill installation and third-party-hosted MCP gateway make this medium-high risk rather than benign.

Confidence: 81%Severity: 76%
Audit Metadata
Analyzed At
Apr 2, 2026, 12:25 AM
Package URL
pkg:socket/skills-sh/gate%2Fgate-skills%2Fgate-mcp-codex-installer%2F@35f743707bb634953ea727f74bdb97dba927db4f