ozon-mcp
Warn
Audited by Socket on Sep 11, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s purpose and credential use are broadly consistent with an Ozon Seller MCP integration, and the described data flow is to the official Ozon API rather than an unrelated proxy. However, it installs executable code from an unpinned GitHub repository on a personal account, with incomplete independent verification of the exact repo/package release path. Because the installed code receives Ozon API credentials, the main concern is supply-chain trust rather than confirmed malicious behavior.
Confidence: 87%Severity: 78%
Audit Metadata