mcp-developer

Warn

Audited by Socket on Aug 2, 2026

1 alert found:

Anomaly
AnomalyLOW
references/python-sdk.md

No clear intentional malware/backdoor behavior is evident from the fragment. However, the module contains several security-risk patterns: caller-controlled database execution via db.execute(arguments['query']) without demonstrated parameterization/allowlisting in this snippet; potential sensitive data exposure by returning query results; possible information leakage through logging of full arguments and through error messages; and a privileged config update path with an externalized resource-update notification. Treat as a medium-to-high security risk requiring verification of db.execute parameterization/whitelisting, strict authz, and log redaction/controls.

Confidence: 46%Severity: 62%
Audit Metadata
Analyzed At
Aug 2, 2026, 08:53 PM
Package URL
pkg:socket/skills-sh/Krypton-Kr36%2Fclaude-code-skills%2Fmcp-developer%2F@752283bfcc039c5a2f831d4cca3bc075bb46ed2bb775afcd0b301f58ce7463b6
Security Audit — socket — mcp-developer