rudder-mcp-setup

Warn

Audited by Socket on Jun 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s purpose and configuration steps are internally consistent with RudderStack’s official MCP docs, and data flows go to the expected RudderStack domain. However, the setup depends on a non-RudderStack third-party npm package (`mcp-remote`) to handle OAuth/MCP traffic, which creates a meaningful supply-chain and credential-forwarding risk even though the package is publicly versioned and documented.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 16, 2026, 05:31 AM
Package URL
pkg:socket/skills-sh/rudderlabs%2Frudder-agent-skills%2Frudder-mcp-setup%2F@4171dd5e22f4a94f9b5a93f0159eea5f3c44a8dd05898a4fc2e0f922067c37de
Security Audit — socket — rudder-mcp-setup