mcp-installer

Fail

Audited by Socket on Mar 11, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
references/mcps/supabase.md

The manifest itself contains no malicious code, but it documents running third-party code via npx with a high-privilege SUPABASE_ACCESS_TOKEN injected into the environment. This presents a supply-chain and credential-exposure risk: if the @supabase/mcp-server package or any of its dependencies are malicious or compromised, the token and managed projects/databases could be abused. Mitigations: obtain and audit the package source, pin versions, use least-privilege/time-limited tokens, and avoid exposing tokens in logs or unsecured environments.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 11, 2026, 09:19 AM
Package URL
pkg:socket/skills-sh/justinlevinedotme%2Fjalco-opencode%2Fmcp-installer%2F@78cd7e9d64ad5640e91c191180001dd55b9b7078