semantic-model-authoring
Warn
Audited by Socket on Sep 18, 2026
1 alert found:
AnomalyAnomalyapm.yml
LOWAnomalyLOW
apm.yml
No direct malicious behavior is present in this manifest. It does introduce a notable supply-chain risk by automatically executing an unpinned npm package at `latest` and exposing all MCP tools. Pin a reviewed package version and preferably verify package integrity, and restrict the enabled tool set where possible.
Confidence: 98%Severity: 62%
Audit Metadata