smoke-test

Warn

Audited by Socket on Mar 2, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The best-supported assessment indicates a well-scoped, CLI-driven smoke-test workflow that scaffolds a Mastra project and exercises the Studio UI via a controlled MCP browser automation flow. While the activity appears benign and aligned with its stated purpose, the operation introduces typical security concerns around supply-chain integrity and secret handling. Recommend monitoring for (1) secure handling and masking of API keys in logs and .env, (2) secured MCP server access and minimal exposure to localhost, and (3) integrity checks for create-mastra and dependencies to mitigate supply-chain risk. Overall risk is moderate due to external dependencies and browser-automation surface, but no evidence of malicious behavior is detected in the provided fragment.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 2, 2026, 10:28 AM
Package URL
pkg:socket/skills-sh/Alot1z%2Fmastra-core-cli%2Fsmoke-test%2F@47f744936544dcda9802ee16c1e64c73ba01d2ab