monte-carlo-monitoring-advisor
Warn
Audited by Socket on Apr 24, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill's capabilities are mostly coherent with Monte Carlo monitoring and observability, and its data flows generally target official Monte Carlo services. The main security concern is the surrounding documented MCP setup that forwards Monte Carlo credentials through third-party `mcp-remote` code fetched via unpinned `npx`, creating meaningful supply-chain and credential-forwarding risk despite otherwise aligned purpose.
Confidence: 87%Severity: 74%
Audit Metadata