api-integration

Warn

Audited by Socket on Sep 4, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s purpose and capabilities mostly align as a documentation-style API integration guide, and there is no clear credential theft or malicious exfiltration. However, it asks the agent/user to execute an unpinned npm package with ambiguous publisher/package provenance (`apidog-mcp-server@latest` vs `@apidog/mcp-server`), so install trust is weaker than expected and raises medium supply-chain risk.

Confidence: 89%Severity: 58%
Audit Metadata
Analyzed At
Sep 4, 2026, 08:19 PM
Package URL
pkg:socket/skills-sh/involvex%2Finvolvex-claude-marketplace%2Fapi-integration%2F@4ade357fc23cd944c08fc982c243bae4d88daffb57a665a20b15710583a3f488
Security Audit — socket — api-integration