iFinD-Finance-Data
Warn
Audited by Socket on May 9, 2026
1 alert found:
SecuritySecuritymcp_config.json
MEDIUMSecurityMEDIUM
mcp_config.json
The provided fragment contains a hardcoded authentication secret (auth_token). While there is no executable logic here to prove malware, this is a significant supply-chain credential leakage risk; the token should be treated as compromised and rotated, and the secret should be removed from any distributed artifacts/history.
Confidence: 80%Severity: 70%
Audit Metadata