price-target-consensus
Warn
Audited by Socket on Sep 16, 2026
1 alert found:
AnomalyAnomalyreferences/mcp-setup.md
LOWAnomalyLOW
references/mcp-setup.md
The fragment is setup documentation and does not itself contain demonstrated malware. It introduces meaningful supply-chain and credential-exposure risks by executing an unreviewed remote shell script, automatically downloading npm packages with npx, and using the mutable `@latest` tag. Use a pinned, audited package version, review installation scripts, avoid curl-to-shell where possible, and protect the API key. The code fragment alone is insufficient to assess the behavior of the Octagon MCP package or its remote services.
Confidence: 98%Severity: 58%
Audit Metadata