apollo-mcp-server

Warn

Audited by Socket on Mar 10, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

Overall, the skill content is coherent with its stated purpose as a setup and usage guide for Apollo MCP Server. However, the install instructions rely on a curl | sh pattern that fetches and executes a remote script from an external URL, which is a significant supply-chain/remote-execution risk and warrants a Suspicious classification. If the install step is necessary, it should be replaced with a verifiable, signed installer from a trusted registry or provide an alternative, verifiable installation method. Excluding that, the data flows from local configuration and schema to local/remote GraphQL endpoints are standard for this type of tool and are proportionate to the stated purpose.

Confidence: 60%Severity: 55%
Audit Metadata
Analyzed At
Mar 10, 2026, 04:48 AM
Package URL
pkg:socket/skills-sh/apollographql%2Fskills%2Fapollo-mcp-server%2F@720df2c5e216b985d9fa44c4dc46a49e2ed0601f