earnings-product-pipeline

Warn

Audited by Socket on Sep 16, 2026

1 alert found:

Anomaly
AnomalyLOW
references/mcp-setup.md

The fragment is setup documentation and does not itself contain malware. It introduces moderate supply-chain and credential-protection risks by recommending direct remote shell execution and unpinned `npx -y` execution of a mutable npm package, while also placing API keys in plaintext configuration or command contexts. Pin and verify a reviewed package version, avoid piping remote scripts directly to a shell, and protect the API key. Assessment of the MCP package itself requires its source or bundled code.

Confidence: 98%Severity: 58%
Audit Metadata
Analyzed At
Sep 16, 2026, 09:13 PM
Package URL
pkg:socket/skills-sh/octagonai%2Fskills%2Fearnings-product-pipeline%2F@885bdf5886ec078c87e431dc262b7cf243aaabdbb26d35ed78cdfc810f9b95f8
Security Audit — socket — earnings-product-pipeline