commodities-quote
Warn
Audited by Socket on Sep 16, 2026
1 alert found:
AnomalyAnomalyreferences/mcp-setup.md
LOWAnomalyLOW
references/mcp-setup.md
The content is legitimate-looking installation and configuration documentation, not executable package code. No direct malware is evident. The main security concerns are operational supply-chain risks: executing a remote shell script via curl|bash, automatically executing an unpinned npm package with npx -y, using the mutable @latest tag, and granting a third-party MCP server access to an API key and network-connected user queries. Pin package versions, verify provenance and integrity, inspect packages before execution, and store the API key using the host application's secure secret mechanism where available.
Confidence: 98%Severity: 62%
Audit Metadata