ableton-live-mcp-control

Warn

Audited by Socket on May 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is broadly aligned with Ableton automation, but it relies on a third-party MCP server outside the publisher's org, includes transitive installation, and grants the agent arbitrary Python execution with direct project-modifying power. Data flows stay mostly local and there is no clear credential harvesting, so this is high-capability and medium-risk rather than confirmed malware.

Confidence: 85%Severity: 58%
Audit Metadata
Analyzed At
May 16, 2026, 10:49 PM
Package URL
pkg:socket/skills-sh/Aradotso%2Fmcp-skills%2Fableton-live-mcp-control%2F@570b6bd4fe3f6191ce8244a047cf188ba8718db7
Security Audit — socket — ableton-live-mcp-control