secure-ai

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Anomaly
AnomalyLOW
references/supply-chain-mcp.md

No evidence of malware or intentional malicious behavior appears in the supplied fragment. However, validateToolCall is security-incomplete: it ignores supplied parameters and does not enforce parameter constraints or rate limits. If used as the actual gate before tool execution, this could permit command, path, or other argument abuse. Ensure all constraints are enforced before executeTool and independently enforce authentication, authorization, approval, and rate limiting.

Confidence: 97%Severity: 58%
Audit Metadata
Analyzed At
Sep 15, 2026, 11:52 AM
Package URL
pkg:socket/skills-sh/oakoss%2Fagent-skills%2Fsecure-ai%2F@b0ed34ac2dbb79c89afe8de75e369adf75672f448468b46035dc66e72eaa4419
Security Audit — socket — secure-ai