google-docs
Warn
Audited by Socket on Aug 7, 2026
1 alert found:
AnomalyAnomaly.mcp.json
LOWAnomalyLOW
.mcp.json
No direct malicious logic is present in this JSON fragment. However, it configures runtime execution of an external npm package via npx (with auto-confirm "-y") without pinning to a specific version or showing integrity verification. This is a meaningful supply-chain risk: the resolved package content ultimately determines what code executes on the host in "mcp" mode.
Confidence: 62%Severity: 52%
Audit Metadata