NYC

typescript-mcp

Fail

Audited by Socket on Feb 15, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

This skill/documentation is coherent and aligns with its stated purpose: providing templates and patterns to build stateless TypeScript MCP servers on Cloudflare Workers. I found no evidence of malicious code, obfuscation, or credential exfiltration. The primary security risks are operational: examples that accept arbitrary SQL queries or file uploads and any deployment that omits authentication/rate-limiting could be abused. If used as intended with the recommended authentication, input validation, parameterized DB access, and rate-limiting, it is safe to use. Reviewers should pay special attention to the 'query-database' and file upload examples before deploying to production.

Confidence: 80%Severity: 25%
Audit Metadata
Analyzed At
Feb 15, 2026, 08:45 PM
Package URL
pkg:socket/skills-sh/ovachiever%2Fdroid-tings%2Ftypescript-mcp%2F@2553767ef54b268488131272ce4a3cba0062803a