analyze-and-recommend-third-party-optimizations

Warn

Audited by Socket on Feb 16, 2026

1 alert found:

Anomaly
AnomalyLOW
.mcp.json

The configuration is not itself malicious, but it instructs automatic download and execution of remote npm code with no version pinning, no integrity checks, and with '-y' auto-confirmation. This creates a meaningful supply-chain and execution risk: a compromised or malicious @context7/mcp-server package could exfiltrate secrets, modify files, or perform arbitrary actions. Remediation: pin to a vetted version, verify package integrity/signature, run in a restricted sandbox or dedicated ephemeral environment, and review package source before running in sensitive contexts.

Confidence: 75%Severity: 62%
Audit Metadata
Analyzed At
Feb 16, 2026, 12:37 PM
Package URL
pkg:socket/skills-sh/nebutra%2Fnext-unicorn-skill%2Fanalyze-and-recommend-third-party-optimizations%2F@d4cf87fd417d5d11ddf4a6df71698f4aa47000e7