day2-supplement-mcp

Fail

Audited by Socket on Mar 6, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill is an educational lesson for MCP and largely matches its stated purpose, but includes a high-risk supply-chain action: an unpinned npx install that downloads and executes third-party code and registers it with the agent. The fragment itself contains no explicit exfiltration code, hard-coded credentials, or obfuscated payloads, but the transitive installation step is the main security concern — it can enable downstream malicious behavior. Recommend pinning package versions, adding checksums, requiring manual review before install, and limiting the permissions and network access of any installed skill.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 6, 2026, 03:26 PM
Package URL
pkg:socket/skills-sh/eoash%2Fash-skills%2Fday2-supplement-mcp%2F@9555d5c08d370f46e70b0e2ffb68f6a15002ad01