price-target-consensus

Warn

Audited by Socket on Sep 16, 2026

1 alert found:

Anomaly
AnomalyLOW
references/mcp-setup.md

The fragment is setup documentation and does not itself contain demonstrated malware. It introduces meaningful supply-chain and credential-exposure risks by executing an unreviewed remote shell script, automatically downloading npm packages with npx, and using the mutable `@latest` tag. Use a pinned, audited package version, review installation scripts, avoid curl-to-shell where possible, and protect the API key. The code fragment alone is insufficient to assess the behavior of the Octagon MCP package or its remote services.

Confidence: 98%Severity: 58%
Audit Metadata
Analyzed At
Sep 16, 2026, 09:14 PM
Package URL
pkg:socket/skills-sh/octagonai%2Fskills%2Fprice-target-consensus%2F@4bbfda6d8cbb93dbe1a5b9059580c8f62775f2f1d2e4e4a84c079d13f862891f
Security Audit — socket — price-target-consensus