godot-devtool-mcp-server
Warn
Audited by Socket on May 18, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill’s capabilities are largely aligned with a Godot devtool, and the documented data flow is local rather than exfiltrative. Main concern is install trust: the skill published by ara.so directs users to clone and build a personal GitHub repo with no verified same-org relationship, plus the skill grants broad local edit/execute capability typical of a powerful devtool.
Confidence: 84%Severity: 60%
Audit Metadata