prediction-markets-analysis

Fail

Audited by Socket on Mar 19, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
references/mcp-setup.md

The README/configuration document contains no explicit malicious code, but it prescribes practices that materially increase supply-chain and secret-exposure risks: dynamically executing an unpinned npm package via npx (with -y and @latest), passing API keys on command lines, and using a non-OAuth URL that embeds API keys. These behaviors can enable credential leakage or arbitrary code execution if the npm package or registry is compromised. Treat the octagon-mcp package as untrusted until its source and integrity are audited; adopt pinned versions, integrity checks, secure secret storage, and least-privilege/sandboxing when deploying.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 19, 2026, 10:47 AM
Package URL
pkg:socket/skills-sh/octagonai%2Fskills%2Fprediction-markets-analysis%2F@797862c8bf679aa81da20a0948f1aab5803ec18a