Rp1
Medium
- Category
- MCP Rug Pull
- Confidence
- 70% confidence
- Finding
- npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a coherent SocQ integration for researching public Threads data, with expected external API use and reasonable guardrails.
Before installing, users should understand that Threads research queries, target URLs/usernames, task metadata, and the SocQ API key are used with SocQ's hosted service and may consume credits. Prefer a preinstalled or pinned SocQ CLI where possible, keep SOCQ_API_KEY in the environment, avoid submitting secrets or regulated data as research inputs, and confirm cost before large collections.
## Execution 1. Prefer an already configured SocQ MCP server at `https://api.socq.ai/mcp?platforms=threads`; use the typed tool listed in [platform.md](references/platform.md), or compact `socq_execute` when needed. 2. If MCP is unavailable, use `socq` or `npx @socq/cli`. Use REST only as the final fallback. 3. Read [authentication.md](references/authentication.md), keep `SOCQ_API_KEY` in the environment, and never put it in prompts, URLs, committed files, or retained commands. 4. Read [billing.md](references/billing.md), report the expected cost, and obtain confirmation before a paid large-volume or multi-endpoint run.
value: "socq"
description: "Hosted SocQ Threads data tools"
transport: "streamable_http"
url: "https://api.socq.ai/mcp?platforms=threads"Detected: suspicious.exposed_secret_literal