anysearch-mcp-server

Warn

Audited by Socket on Sep 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core purpose and direct data flow to AnySearch are coherent and the official HTTP endpoint appears legitimate, but the alternate proxy setups materially expand trust: unpinned third-party npm CLIs are installed/executed and are given the AnySearch API key. No confirmed malware or deceptive exfiltration is evident, but the credential-forwarding through unrelated proxy tools makes this a medium-high risk skill.

Confidence: 91%Severity: 80%
Audit Metadata
Analyzed At
Sep 16, 2026, 10:31 PM
Package URL
pkg:socket/skills-sh/reason-machines%2Fmcp-skills%2Fanysearch-mcp-server%2F@fd7e97495bd5f28f76e8eabd1f8058efe8fc0acd5a9703bfc3fa1cda83848a09
Security Audit — socket — anysearch-mcp-server