tools
Warn
Audited by Socket on Sep 17, 2026
1 alert found:
AnomalyAnomalyreferences/mcp-apps.md
LOWAnomalyLOW
references/mcp-apps.md
No evidence of intentionally malicious code or obfuscation is present. The material documents legitimate MCP Apps functionality. The main security concern is an authorization boundary in the example route: untrusted widget/request parameters can select servers, invoke tools, and access resources unless the application adds authentication, authorization, allowlisting, validation, rate limiting, and tenant isolation. Treat widget HTML and openLink destinations as untrusted.
Confidence: 97%Severity: 55%
Audit Metadata