tools

Warn

Audited by Socket on Sep 17, 2026

1 alert found:

Anomaly
AnomalyLOW
references/mcp-apps.md

No evidence of intentionally malicious code or obfuscation is present. The material documents legitimate MCP Apps functionality. The main security concern is an authorization boundary in the example route: untrusted widget/request parameters can select servers, invoke tools, and access resources unless the application adds authentication, authorization, allowlisting, validation, rate limiting, and tenant isolation. Treat widget HTML and openLink destinations as untrusted.

Confidence: 97%Severity: 55%
Audit Metadata
Analyzed At
Sep 17, 2026, 05:49 PM
Package URL
pkg:socket/skills-sh/assistant-ui%2Fskills%2Ftools%2F@0eae70128d87dabf79cfebe3308e410eec3d62182445049c879e51b2b772685f
Security Audit — socket — tools