native-mcp
Warn
Audited by Socket on Jun 23, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill’s stated purpose matches its behavior, and its examples align with official MCP documentation, so it is not fundamentally deceptive. However, it normalizes attaching arbitrary third-party MCP servers, forwarding credentials to them, and exposing their tools natively to Claude; this creates meaningful supply-chain and data-flow risk that is broader than a narrow configuration helper.
Confidence: 85%Severity: 58%
Audit Metadata