webmcp-setup

Warn

Audited by Socket on Mar 31, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The stated purpose is coherent for a WebMCP setup skill, but trust is weakened by reliance on live web search, mutable install guidance, and a third-party MCP-B ecosystem with inconsistent publisher provenance. No clear credential theft or exfiltration appears, yet the combination of WebSearch/WebFetch with Bash and file writes creates meaningful supply-chain and prompt-injection risk.

Confidence: 85%Severity: 61%
Audit Metadata
Analyzed At
Mar 31, 2026, 06:09 AM
Package URL
pkg:socket/skills-sh/OrcaQubits%2Fagentic-commerce-skills-plugins%2Fwebmcp-setup%2F@8eb9c87cfb721fdfdd36a74a4f6cb2ba4f73a151