stock-grades
Warn
Audited by Socket on Sep 16, 2026
1 alert found:
AnomalyAnomalyreferences/mcp-setup.md
LOWAnomalyLOW
references/mcp-setup.md
The content is installation documentation and contains no demonstrated malware. The principal security concerns are execution of a remotely downloaded shell script, execution of an unpinned npm package via npx -y and the latest tag, and possible API-key exposure through command lines or configuration files. Review and pin the package version, verify package provenance and integrity, avoid piping unreviewed downloads to a shell, and store the API key using appropriately protected secret management. The referenced package itself requires separate analysis.
Confidence: 98%Severity: 58%
Audit Metadata