kagi-session2api-mcp-server
Warn
Audited by Socket on Sep 16, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill’s search/summarization behavior matches its stated purpose, but it asks users to bypass Kagi’s official API by providing full-account session tokens to a third-party PyPI package from a different publisher. No direct exfiltration endpoint or overt malware is shown, but the credential scope and third-party trust chain are disproportionate versus a normal API integration.
Confidence: 89%Severity: 68%
Audit Metadata