patchxnote-mcp

Warn

Audited by Socket on Sep 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s purpose mostly matches its capabilities, and its security guidance is unusually defensive rather than deceptive. The main concern is transitive trust in an unpinned `npx @latest` CLI that installs/configures the integration and may handle auth state, which creates meaningful supply-chain risk even though the package appears same-project and registry-hosted; overall this is better classified as medium-risk vulnerable than malicious.

Confidence: 86%Severity: 52%
Audit Metadata
Analyzed At
Sep 16, 2026, 04:16 AM
Package URL
pkg:socket/skills-sh/zsts119%2Fpatchx-freenote-agent%2Fpatchxnote-mcp%2F@2e48aaa6a5819f86cd14e92fa300987904059368c3c79cafdf5df7ec1ebd2e09
Security Audit — socket — patchxnote-mcp