native-mcp

Warn

Audited by Socket on Jun 23, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s stated purpose matches its behavior, and its examples align with official MCP documentation, so it is not fundamentally deceptive. However, it normalizes attaching arbitrary third-party MCP servers, forwarding credentials to them, and exposing their tools natively to Claude; this creates meaningful supply-chain and data-flow risk that is broader than a narrow configuration helper.

Confidence: 85%Severity: 58%
Audit Metadata
Analyzed At
Jun 23, 2026, 05:25 PM
Package URL
pkg:socket/skills-sh/AlexAI-MCP%2Fhermes-CCC%2Fnative-mcp%2F@82b4eb0a850a903e564b5aff634fb5c9ba548dc0ef18dbf285534c25fb0f79c7
Security Audit — socket — native-mcp