pal-mcp-expert

Fail

Audited by Socket on Feb 16, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
references/installation-config.md

The provided document itself is not direct malware, but it prescribes several high-risk supply-chain and secret-management patterns: executing remote installers via curl|sh and dynamic runtime fetching/execution via uvx --from git+..., plus persisting API keys to disk and environment. These patterns substantially increase the risk that a compromised upstream or malicious installer could achieve arbitrary code execution or credential theft. Recommend operators avoid piping remote scripts to shell, pin and verify upstream artifacts, inspect fetched code before running, restrict .env permissions, prefer short-lived/scoped keys, and run installation in isolated, least-privilege environments.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 16, 2026, 11:40 AM
Package URL
pkg:socket/skills-sh/mamba-mental%2Fagent-skill-manager%2Fpal-mcp-expert%2F@74cf131a11408f76c1902cc5de823679b5cf0ba7