earnings-call-analysis
Warn
Audited by Socket on Sep 16, 2026
1 alert found:
AnomalyAnomalyreferences/mcp-setup.md
LOWAnomalyLOW
references/mcp-setup.md
The fragment is setup documentation and does not itself contain malware. It introduces moderate supply-chain and credential-protection risks by recommending direct remote shell execution and unpinned `npx -y` execution of a mutable npm package, while also placing API keys in plaintext configuration or command contexts. Pin and verify a reviewed package version, avoid piping remote scripts directly to a shell, and protect the API key. Assessment of the MCP package itself requires its source or bundled code.
Confidence: 98%Severity: 58%
Audit Metadata