commodities-quote

Warn

Audited by Socket on Sep 16, 2026

1 alert found:

Anomaly
AnomalyLOW
references/mcp-setup.md

The content is legitimate-looking installation and configuration documentation, not executable package code. No direct malware is evident. The main security concerns are operational supply-chain risks: executing a remote shell script via curl|bash, automatically executing an unpinned npm package with npx -y, using the mutable @latest tag, and granting a third-party MCP server access to an API key and network-connected user queries. Pin package versions, verify provenance and integrity, inspect packages before execution, and store the API key using the host application's secure secret mechanism where available.

Confidence: 98%Severity: 62%
Audit Metadata
Analyzed At
Sep 16, 2026, 09:13 PM
Package URL
pkg:socket/skills-sh/octagonai%2Fskills%2Fcommodities-quote%2F@59f6b167b68fbbc96e41da64892871d0066824fea53d1d5cdd10de862e9b7978
Security Audit — socket — commodities-quote