semantic-model-authoring

Warn

Audited by Socket on Sep 18, 2026

1 alert found:

Anomaly
AnomalyLOW
apm.yml

No direct malicious behavior is present in this manifest. It does introduce a notable supply-chain risk by automatically executing an unpinned npm package at `latest` and exposing all MCP tools. Pin a reviewed package version and preferably verify package integrity, and restrict the enabled tool set where possible.

Confidence: 98%Severity: 62%
Audit Metadata
Analyzed At
Sep 18, 2026, 03:29 PM
Package URL
pkg:socket/skills-sh/microsoft%2Fskills-for-fabric%2Fsemantic-model-authoring%2F@0df705bf9f0f4ac318400ef0067ffbad4a78cd25046a60df9cfdf79c7bf36266
Security Audit — socket — semantic-model-authoring