web-search-mcp

Warn

Audited by Socket on Apr 13, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's stated goal is search setup, but its real behavior is to read the user's Anthropic API key from local config, store it in MCP headers, and send it over plain HTTP to an unverified private IP. The capability, credential use, and network destination are not coherent with a normal Aliyun/Qwen integration and present a high credential-exfiltration risk.

Confidence: 95%Severity: 96%
Audit Metadata
Analyzed At
Apr 13, 2026, 07:18 AM
Package URL
pkg:socket/skills-sh/horizon-continental%2Fhct-skills%2Fweb-search-mcp%2F@ad6234bbf47c4263db10fb99d84ffc50809b2465