monte-carlo-monitoring-advisor

Warn

Audited by Socket on Apr 24, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's capabilities are mostly coherent with Monte Carlo monitoring and observability, and its data flows generally target official Monte Carlo services. The main security concern is the surrounding documented MCP setup that forwards Monte Carlo credentials through third-party `mcp-remote` code fetched via unpinned `npx`, creating meaningful supply-chain and credential-forwarding risk despite otherwise aligned purpose.

Confidence: 87%Severity: 74%
Audit Metadata
Analyzed At
Apr 24, 2026, 05:59 PM
Package URL
pkg:socket/skills-sh/monte-carlo-data%2Fmc-agent-toolkit%2Fmonte-carlo-monitoring-advisor%2F@cb2fa17bc7808aaff22b4d9cf090b96e3b511bcb