mcp-api-key-auth

Fail

Audited by Socket on Mar 9, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill’s footprint is coherent with its stated purpose: it provides API-key-based MCP authentication and usage tracking for a stock data service, with proper JWT-protected management endpoints and a clearly defined data path to the MCP server and ClickHouse. The minimal credential exposure (single-shot API key display) and absence of external data sinks reduce risk. Overall, the implementation appears benign with low to moderate security risk, proportional to its scope of managing credentials and usage data.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 9, 2026, 08:52 AM
Package URL
pkg:socket/skills-sh/Yourdaylight%2Fstock_datasource%2Fmcp-api-key-auth%2F@103bf3dfd52ad6b575163f0e49b26b2e691a6cdc