agent-creator

Warn

Audited by Socket on Jul 7, 2026

1 alert found:

Anomaly
AnomalyLOW
assets/mcp-ordering-correct.toml

No direct malicious code is present in this configuration fragment, and there are no obvious secrets or obfuscation indicators. However, it configures high-impact runtime execution by starting an MCP server through /usr/local/bin/npx with a package spec (@scope/example-mcp-server) and -y, implying dynamic package resolution/install-and-run behavior. Without visible version pinning/integrity enforcement in this snippet, the main risk is supply-chain compromise or dependency substitution leading to arbitrary code execution within the host’s privileges (mitigated only partially by read-only sandbox intent).

Confidence: 66%Severity: 52%
Audit Metadata
Analyzed At
Jul 7, 2026, 02:25 AM
Package URL
pkg:socket/skills-sh/JsonLee12138%2FvibeRig%2Fagent-creator%2F@50e13fdf3c54212405db3027b5537d325113c54e14c36de919c00840957d80bd
Security Audit — socket — agent-creator