sec-risk-factors

Warn

Audited by Socket on Sep 16, 2026

1 alert found:

Anomaly
AnomalyLOW
references/mcp-setup.md

No direct malware or malicious behavior is demonstrated because the submission contains documentation only. It does introduce meaningful supply-chain and secret-handling risks: remote shell execution via curl-pipe-to-bash, execution of an unpinned or mutable npm package through npx, and API-key placement in commands or configuration. Pin package versions, verify package provenance and integrity, avoid piping remote scripts directly to a shell, and protect the API key.

Confidence: 98%Severity: 62%
Audit Metadata
Analyzed At
Sep 16, 2026, 09:14 PM
Package URL
pkg:socket/skills-sh/octagonai%2Fskills%2Fsec-risk-factors%2F@a45074e0545dbf886038acec8a38201815201b5606e2640cfbe7a27fb30a7ce7
Security Audit — socket — sec-risk-factors