sec-debt-covenant
Warn
Audited by Socket on Sep 16, 2026
1 alert found:
AnomalyAnomalyreferences/mcp-setup.md
LOWAnomalyLOW
references/mcp-setup.md
No direct malware or malicious behavior is demonstrated because the submission contains documentation only. It does introduce meaningful supply-chain and secret-handling risks: remote shell execution via curl-pipe-to-bash, execution of an unpinned or mutable npm package through npx, and API-key placement in commands or configuration. Pin package versions, verify package provenance and integrity, avoid piping remote scripts directly to a shell, and protect the API key.
Confidence: 98%Severity: 62%
Audit Metadata