day2-mcp-and-context-sync
Warn
Audited by Socket on Mar 2, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
The fragment is a coherent, purpose-aligned training scaffold for MCP and Context Sync with standard install steps from public registries. There are no evident malicious payloads, credential harvesting hooks, or data exfiltration mechanisms inherent to the fragment. The primary concerns are typical supply-chain risk from dynamic skill installation (npx/npm) and the potential for automated tool interactions that could be abused if executed by an untrusted agent. Overall, classify as BENIGN with elevated caution due to dynamic install/execution patterns.
Confidence: 70%Severity: 65%
Audit Metadata