godot-mcp-native
Warn
Audited by Socket on May 17, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The core capabilities match the stated purpose of controlling a Godot project, so this is not fundamentally deceptive. Main concerns are proportionality and trust-chain: a local HTTP control server with authentication disabled by default, powerful script/runtime execution features, and an extra npm/npx bridge from a different package. Overall this looks coherent but materially risky rather than outright malicious.
Confidence: 84%Severity: 62%
Audit Metadata