seo-audit

Warn

Audited by Socket on Sep 1, 2026

1 alert found:

Anomaly
AnomalyLOW
.mcp.json

This fragment is declarative configuration, not malicious code itself. However, it authorizes runtime download-and-execution of an unpinned third-party package ("shadcn@latest") via npx, creating a meaningful supply-chain execution risk: the effective MCP server code can change over time and could be swapped by a compromised upstream release.

Confidence: 70%Severity: 60%
Audit Metadata
Analyzed At
Sep 1, 2026, 12:20 PM
Package URL
pkg:socket/skills-sh/seo-skills%2Fseo-audit-skill%2Fseo-audit%2F@26adce40e912860e44fa47d28857b48fc7b19689
Security Audit — socket — seo-audit