minimax-understand-image
Fail
Audited by Socket on Mar 4, 2026
1 alert found:
MalwareMalwareSKILL.md
HIGHMalwareHIGH
SKILL.md
The approach aligns with its stated goal of enabling image understanding via a local MCP server but relies on high-risk patterns (remote installer, plaintext API key placeholders, multiple mirrors). To improve security, adopt signed, verifiable installation methods, remove plaintext placeholder credentials, enforce least privilege and strong file permissions, and ensure IPC is strictly local with explicit data sanitization and minimal logging. Overall risk is moderate to high due to supply-chain and credential handling concerns.
Confidence: 95%Severity: 90%
Audit Metadata