sec-footnotes-analysis

Warn

Audited by Socket on Sep 16, 2026

1 alert found:

Anomaly
AnomalyLOW
references/mcp-setup.md

No direct malware or malicious behavior is demonstrated because the submission contains documentation only. It does introduce meaningful supply-chain and secret-handling risks: remote shell execution via curl-pipe-to-bash, execution of an unpinned or mutable npm package through npx, and API-key placement in commands or configuration. Pin package versions, verify package provenance and integrity, avoid piping remote scripts directly to a shell, and protect the API key.

Confidence: 98%Severity: 62%
Audit Metadata
Analyzed At
Sep 16, 2026, 09:15 PM
Package URL
pkg:socket/skills-sh/octagonai%2Fskills%2Fsec-footnotes-analysis%2F@c1f6d6d4805b83c82fa0929a9c25cf1d72a0437fe3cb4330681cb02385eb65a9
Security Audit — socket — sec-footnotes-analysis