sec-segment-reporting

Warn

Audited by Socket on Sep 16, 2026

1 alert found:

Anomaly
AnomalyLOW
references/mcp-setup.md

No direct malware or malicious behavior is demonstrated because the submission contains documentation only. It does introduce meaningful supply-chain and secret-handling risks: remote shell execution via curl-pipe-to-bash, execution of an unpinned or mutable npm package through npx, and API-key placement in commands or configuration. Pin package versions, verify package provenance and integrity, avoid piping remote scripts directly to a shell, and protect the API key.

Confidence: 98%Severity: 62%
Audit Metadata
Analyzed At
Sep 16, 2026, 09:16 PM
Package URL
pkg:socket/skills-sh/octagonai%2Fskills%2Fsec-segment-reporting%2F@678e329e62149574d198c7bf42725a1de6f952034858c12c5b9fa4cfc4567034
Security Audit — socket — sec-segment-reporting