totp-mcp-server

Warn

Audited by Socket on Aug 26, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/totp_mcp_server.py

No clear evidence of classic supply-chain malware (no obfuscation, no dynamic execution, no network exfiltration, and no destructive behavior). However, this module intentionally issues live TOTP codes via an MCP interface, which is a high-impact security capability and becomes a significant threat if the MCP transport/authorization is weak. Additional concerns include audit-log metadata exposure and an unsanitized file-path construction for the account name in the file backend (mitigated in practice by the membership check against stored_accounts()).

Confidence: 60%Severity: 55%
Audit Metadata
Analyzed At
Aug 26, 2026, 11:53 AM
Package URL
pkg:socket/skills-sh/paldom%2F2fa-agents%2Ftotp-mcp-server%2F@94793c39e6ec16c6927020735b5310106ab33776b03021d33cb82fa5abc44c1a
Security Audit — socket — totp-mcp-server