mcp-server

Warn

Audited by Socket on Sep 18, 2026

1 alert found:

Security
SecurityMEDIUM
examples/bad-order-tools.java

The code exposes an unrestricted remote command execution capability through a tool. This is a critical security risk unless the tool is strictly trusted and isolated. The implementation should avoid shell execution where possible; otherwise it should enforce authorization, use a strict command allowlist, pass structured arguments without shell interpretation, sandbox execution, restrict privileges, and avoid logging sensitive commands to stdout.

Confidence: 99%Severity: 99%
Audit Metadata
Analyzed At
Sep 18, 2026, 08:46 AM
Package URL
pkg:socket/skills-sh/rrezartprebreza%2Fspring-boot-skills%2Fmcp-server%2F@b7f657f174d90b05ad66cb09844d001a36050899f4fc595e25bc6819e51bc863
Security Audit — socket — mcp-server