godot-devtool-mcp-server

Warn

Audited by Socket on May 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s capabilities are largely aligned with a Godot devtool, and the documented data flow is local rather than exfiltrative. Main concern is install trust: the skill published by ara.so directs users to clone and build a personal GitHub repo with no verified same-org relationship, plus the skill grants broad local edit/execute capability typical of a powerful devtool.

Confidence: 84%Severity: 60%
Audit Metadata
Analyzed At
May 18, 2026, 12:51 PM
Package URL
pkg:socket/skills-sh/Aradotso%2Fdevtools-skills%2Fgodot-devtool-mcp-server%2F@325152c4c25b3ebac5d1e2ea27698dffd792a026