charge-pix

Warn

Audited by Socket on Apr 20, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s purpose and official Kobana API/MCP data flows are mostly coherent, and the same-org kobana-mcp-charge package looks legitimate. However, the hosted MCP path materially increases risk by using unpinned third-party mcp-remote and forwarding the bearer token through it, plus the docs encourage plaintext token storage in config files.

Confidence: 88%Severity: 82%
Audit Metadata
Analyzed At
Apr 20, 2026, 06:04 PM
Package URL
pkg:socket/skills-sh/universokobana%2Fkobana-agent-skills%2Fcharge-pix%2F@c2beb24885ef6cddd2951cb2110f37fc81ee76cd
Security Audit — socket — charge-pix