google-contacts

Warn

Audited by Socket on Aug 24, 2026

1 alert found:

Anomaly
AnomalyLOW
.mcp.json

This JSON snippet itself is not malicious—it is a declarative launcher configuration. However, it instructs the host to execute external code via `npx -y @zapier/google-contacts-connector mcp` with no visible version pinning or integrity checking in the snippet. That makes the main concern supply-chain execution risk (unexpected package updates or tampering), rather than direct malware behavior within this file.

Confidence: 62%Severity: 52%
Audit Metadata
Analyzed At
Aug 24, 2026, 02:44 PM
Package URL
pkg:socket/skills-sh/zapier%2Fconnectors%2Fgoogle-contacts%2F@64aff7a90a5744640e11e503fdbc306f0e9a00ce6c39e6748df07d1f1c10d6d1
Security Audit — socket — google-contacts