synctx-mcp

Warn

Audited by Socket on Mar 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s stated purpose matches collaboration and deal orchestration, but its actual footprint is high risk: it forwards reusable auth credentials to an unspecified MCP service, ingests untrusted external content, and authorizes autonomous financial blockchain actions including token approvals and settlement steps. The biggest issue is not obvious malware, but an under-specified trust boundary combined with pre-authorized real-world transactions.

Confidence: 84%Severity: 82%
Audit Metadata
Analyzed At
Mar 16, 2026, 12:43 PM
Package URL
pkg:socket/skills-sh/synctxai%2Fsynctx%2Fsynctx-mcp%2F@0712a4be544df7aec19a4e9f6e633e80ada07653
Security Audit — socket — synctx-mcp