seo-audit
Warn
Audited by Socket on Sep 1, 2026
1 alert found:
AnomalyAnomaly.mcp.json
LOWAnomalyLOW
.mcp.json
This fragment is declarative configuration, not malicious code itself. However, it authorizes runtime download-and-execution of an unpinned third-party package ("shadcn@latest") via npx, creating a meaningful supply-chain execution risk: the effective MCP server code can change over time and could be swapped by a compromised upstream release.
Confidence: 70%Severity: 60%
Audit Metadata