build-custom-mcp-server

Fail

Audited by Snyk on Jun 22, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E006: Malicious code pattern detected in skill scripts.

  • Malicious code pattern detected (high risk: 0.90). This MCP server intentionally exposes tools that allow a connected AI to run arbitrary SELECT database queries and invoke analysis handlers, which enables straightforward data exfiltration to remote agents and—if handlers perform unsanitized shell/DB operations or access secrets—could allow remote abuse or credential leakage; there is no obfuscated/backdoor payload in the code, but the design is high-risk when connected to sensitive systems.

Issues (1)

E006
CRITICAL

Malicious code pattern detected in skill scripts.

Audit Metadata
Risk Level
CRITICAL
Analyzed
Jun 22, 2026, 12:13 PM
Issues
1
Security Audit — snyk — build-custom-mcp-server