minimax-web-search

Fail

Audited by Socket on Mar 4, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The skill's stated purpose (performing web searches via a MiniMax MCP server) aligns with the capabilities described (install uvx, install/run minimax-coding-plan-mcp, read API key, call web_search). However, there are material supply-chain risks: the README recommends running a remote installer via curl | sh, installing a third-party MCP package that will execute locally, and storing the API key in plaintext. These are not direct proofs of malicious behavior but are high-risk patterns for credential leakage and supply-chain compromise. Recommend avoiding pipe-to-shell install or auditing the installer and the minimax-coding-plan-mcp package before running; secure the API key (restrict file permissions or use a secret manager).

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Mar 4, 2026, 06:54 AM
Package URL
pkg:socket/skills-sh/thincher%2Fawsome_skills%2Fminimax-web-search%2F@702dadbd67362a32184b648017ab9aa9a9ebe933