ableton-live-mcp-control
Warn
Audited by Socket on May 16, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill is broadly aligned with Ableton automation, but it relies on a third-party MCP server outside the publisher's org, includes transitive installation, and grants the agent arbitrary Python execution with direct project-modifying power. Data flows stay mostly local and there is no clear credential harvesting, so this is high-capability and medium-risk rather than confirmed malware.
Confidence: 85%Severity: 58%
Audit Metadata