company-market-cap
Warn
Audited by Socket on Sep 16, 2026
1 alert found:
AnomalyAnomalyreferences/mcp-setup.md
LOWAnomalyLOW
references/mcp-setup.md
No direct malicious code is present because the fragment is setup documentation. It does, however, recommend two notable supply-chain-risk patterns: piping a remote shell script into bash and automatically downloading/executing an unpinned npm package with npx, including the mutable `latest` tag. The API key should be stored through a protected environment or secret manager rather than embedded in shell commands or broadly accessible configuration files. Review the actual `octagon-mcp` package, its dependencies, release integrity, and network behavior before deployment.
Confidence: 98%Severity: 62%
Audit Metadata