cve-mcp-server-security-intelligence

Warn

Audited by Socket on May 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the capabilities largely match a CVE/threat-intelligence skill, and the stated outbound-only HTTPS model is plausible. The main concern is install/provenance inconsistency: the skill is presented as an ara.so/MCP Skills item, but the package and source are attributed to a different publisher (`mukul975`). Combined with the large set of API credentials this creates a meaningful trust and credential-forwarding risk, even without evidence of confirmed malicious behavior.

Confidence: 82%Severity: 69%
Audit Metadata
Analyzed At
May 16, 2026, 08:50 PM
Package URL
pkg:socket/skills-sh/Aradotso%2Fmcp-skills%2Fcve-mcp-server-security-intelligence%2F@1e70e8a789ba276bab03a5a2a5c5451bb3690c3e
Security Audit — socket — cve-mcp-server-security-intelligence