agents-mcp
Warn
Audited by Socket on Sep 23, 2026
1 alert found:
AnomalyAnomalyreferences/mcp-patterns.md
LOWAnomalyLOW
references/mcp-patterns.md
The fragment contains legitimate MCP integration examples, not apparent malware. It nevertheless demonstrates high-impact interfaces: arbitrary SQL execution, authenticated outbound API calls, and filesystem modification. The filesystem prefix check and direct URL/query handling require hardening before production use. Risk is primarily dependent on MCP authentication, authorization, database privileges, API endpoint controls, and deployment trust boundaries.
Confidence: 97%Severity: 68%
Audit Metadata