coinmarketcap-mcp-skill

Warn

Audited by Socket on Mar 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core purpose is coherent and the network endpoint is official CoinMarketCap, but the skill unnecessarily routes authentication and execution through the external `uxc` CLI and a transitive `uxc` skill. This is not confirmed malicious, yet it expands trust and forwards API credentials to third-party tooling beyond what CoinMarketCap's direct MCP setup requires.

Confidence: 87%Severity: 56%
Audit Metadata
Analyzed At
Mar 15, 2026, 03:57 AM
Package URL
pkg:socket/skills-sh/holon-run%2Fuxc%2Fcoinmarketcap-mcp-skill%2F@d53ee0811e15ebbf705c438a24c6f45cd91551ba