google-analytics

Warn

Audited by Socket on Aug 7, 2026

1 alert found:

Anomaly
AnomalyLOW
.mcp.json

This fragment does not show direct malicious behavior; it is configuration that launches a third-party connector via npx. The main concern is supply-chain exposure: runtime auto-fetch/auto-install behavior ("npx -y"), absence of explicit version pinning, and no visible integrity pinning in the snippet. Review/lock the exact connector version and ensure package integrity controls are in place to reduce the risk of executing tampered registry content.

Confidence: 70%Severity: 50%
Audit Metadata
Analyzed At
Aug 7, 2026, 08:54 PM
Package URL
pkg:socket/skills-sh/zapier%2Fconnectors%2Fgoogle-analytics%2F@25d765c9a49360e35c5d97b964ac3f900cbdc761b625088672fd7df458d4a888
Security Audit — socket — google-analytics