google-docs

Warn

Audited by Socket on Aug 7, 2026

1 alert found:

Anomaly
AnomalyLOW
.mcp.json

No direct malicious logic is present in this JSON fragment. However, it configures runtime execution of an external npm package via npx (with auto-confirm "-y") without pinning to a specific version or showing integrity verification. This is a meaningful supply-chain risk: the resolved package content ultimately determines what code executes on the host in "mcp" mode.

Confidence: 62%Severity: 52%
Audit Metadata
Analyzed At
Aug 7, 2026, 08:57 PM
Package URL
pkg:socket/skills-sh/zapier%2Fconnectors%2Fgoogle-docs%2F@fee12a12300a30962d790562168cc01af4a3efc91781d18a66431b94cbdefdf9
Security Audit — socket — google-docs