build-mcp-use-server

Fail

Audited by Socket on May 17, 2026

2 alerts found:

SecurityObfuscated File
SecurityMEDIUM
references/30-workflows/01-stateless-vercel-tool-server.md

No direct malware/backdoor behavior is evident in this module. However, the fetch-json tool provides attacker-controlled server-side fetching with only syntactic URL validation, creating a significant SSRF/egress and potential DoS risk if exposed to untrusted callers. echo and geo-from-headers are comparatively low risk. Authentication/egress/rate-limit controls are not shown here, so risk depends on upstream protections outside this file.

Confidence: 66%Severity: 72%
Obfuscated FileHIGH
references/31-canonical-examples/10-mcp-slide-deck.md

The described system presents a benign architectural pattern for streaming slides with in-memory asset storage and per-index editing. However, the lack of authentication, persistence, and input validation introduces meaningful security and reliability risks (unauthorized access, memory-based DoS, data integrity concerns). Implementing proper access controls, durable storage, and input validation is essential before deployment in a production environment.

Confidence: 98%
Audit Metadata
Analyzed At
May 17, 2026, 10:54 PM
Package URL
pkg:socket/skills-sh/yigitkonur%2Fskills-by-yigitkonur%2Fbuild-mcp-use-server%2F@c7a02e606cc4e8bf6df92f0aa1e3897a1036eb52
Security Audit — socket — build-mcp-use-server