remote-cluster-agent

Warn

Audited by Socket on May 19, 2026

1 alert found:

Anomaly
AnomalyLOW
mcp-server/setup.sh

No direct malicious indicators (no obfuscated payloads, secrets, exfiltration, or backdoor behavior) are present in this Bash fragment. However, it performs a supply-chain-sensitive editable install into a persistent venv and forwards attacker-controlled SSH command text and user-controlled paths into the registered MCP server via environment variables. The security of the system hinges on how mcp_remote_server.py interprets and executes NODES/agent/path values; without validation, this could enable command injection or remote execution. Overall: low-to-moderate malware likelihood in this specific fragment, with moderate security risk due to delegation of untrusted inputs to a long-running server.

Confidence: 62%Severity: 50%
Audit Metadata
Analyzed At
May 19, 2026, 07:40 AM
Package URL
pkg:socket/skills-sh/jiahao-shao1%2Fsjh-skills%2Fremote-cluster-agent%2F@190777d2ae0652dcb04a374f18d8174e73c101cd
Security Audit — socket — remote-cluster-agent