stock-historical-index
Warn
Audited by Socket on Sep 16, 2026
1 alert found:
AnomalyAnomalyreferences/mcp-setup.md
LOWAnomalyLOW
references/mcp-setup.md
The fragment is setup documentation rather than malware. It presents supply-chain and credential-handling risks because it executes an unpinned latest npm package with npx, recommends a remote curl-to-bash installer, and exposes API keys through command lines or plaintext configuration files. Verify the package publisher, pin and audit a known version, use secure secret storage, and review the MCP server's network and data handling before deployment.
Confidence: 98%Severity: 62%
Audit Metadata