kagi-session2api-mcp-server

Warn

Audited by Socket on Sep 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s search/summarization behavior matches its stated purpose, but it asks users to bypass Kagi’s official API by providing full-account session tokens to a third-party PyPI package from a different publisher. No direct exfiltration endpoint or overt malware is shown, but the credential scope and third-party trust chain are disproportionate versus a normal API integration.

Confidence: 89%Severity: 68%
Audit Metadata
Analyzed At
Sep 16, 2026, 10:34 PM
Package URL
pkg:socket/skills-sh/reason-machines%2Fmcp-skills%2Fkagi-session2api-mcp-server%2F@b0108d4e462d4033ae3947725531118e55db1cac2b7fa08d798f2aecb42f601c
Security Audit — socket — kagi-session2api-mcp-server