godot-mcp-native

Warn

Audited by Socket on May 17, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core capabilities match the stated purpose of controlling a Godot project, so this is not fundamentally deceptive. Main concerns are proportionality and trust-chain: a local HTTP control server with authentication disabled by default, powerful script/runtime execution features, and an extra npm/npx bridge from a different package. Overall this looks coherent but materially risky rather than outright malicious.

Confidence: 84%Severity: 62%
Audit Metadata
Analyzed At
May 17, 2026, 11:55 AM
Package URL
pkg:socket/skills-sh/Aradotso%2Fmcp-skills%2Fgodot-mcp-native%2F@6cc6170f2b3e32ac184eb78969fadb87e747a86b
Security Audit — socket — godot-mcp-native