kindly-web-search-mcp-server

Warn

Audited by Socket on Sep 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The skill's capabilities broadly match its stated web-search purpose, and its declared credentials are proportionate to search/GitHub extraction. The main concern is install trust: it asks users to install uv via pipe-to-shell and then run the MCP server directly from an unpinned third-party GitHub repo while forwarding API keys and optional GitHub tokens into that code. This is suspicious from a supply-chain standpoint but not strong evidence of malicious intent.

Confidence: 87%Severity: 66%
Audit Metadata
Analyzed At
Sep 16, 2026, 10:34 PM
Package URL
pkg:socket/skills-sh/reason-machines%2Fmcp-skills%2Fkindly-web-search-mcp-server%2F@0ef017ce65e07e8702899fc69af0037cdb94cb0d3f4ba87bcda7a03f3d5aa468
Security Audit — socket — kindly-web-search-mcp-server