tapd
Warn
Audited by Socket on Jun 17, 2026
2 alerts found:
SecurityAnomalySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
Anomalyreferences/bootstrap-cursor.md
LOWAnomalyLOW
references/bootstrap-cursor.md
No direct malware is evidenced in the provided fragment because it is configuration-only. However, it creates a meaningful supply-chain and credential-exposure risk by running a third-party MCP server via uvx (runtime code materialization/execution) and passing a TAPD access token into that third-party process. This warrants review of package provenance/integrity and token scope minimization, and verification of uvx/package-fetch behavior in the user environment.
Confidence: 100%Severity: 60%
Audit Metadata