ozon-mcp

Warn

Audited by Socket on Sep 11, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s purpose and credential use are broadly consistent with an Ozon Seller MCP integration, and the described data flow is to the official Ozon API rather than an unrelated proxy. However, it installs executable code from an unpinned GitHub repository on a personal account, with incomplete independent verification of the exact repo/package release path. Because the installed code receives Ozon API credentials, the main concern is supply-chain trust rather than confirmed malicious behavior.

Confidence: 87%Severity: 78%
Audit Metadata
Analyzed At
Sep 11, 2026, 02:17 PM
Package URL
pkg:socket/skills-sh/ilyautov%2Fozon-mcp-ru%2Fozon-mcp%2F@704e611c762c0b86277551fd94104c834e3e149e8cc26551222e588a15f1a8e7
Security Audit — socket — ozon-mcp