log-analytics
Warn
Audited by Socket on May 8, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The core OpenSearch access is largely aligned with the stated purpose and uses a same-org published MCP package, but the skill still carries medium risk from unpinned uvx execution, credential forwarding to MCP code, an unrelated optional search MCP dependency, and especially the documented SSL verification disablement.
Confidence: 87%Severity: 62%
Audit Metadata