lanhu-mcp-collaboration

Warn

Audited by Socket on May 17, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core capabilities broadly match the stated Lanhu collaboration purpose, and the documented network destinations are mostly official. However, trust is weakened because the skill is published by one party while installation directs users to a different GitHub repo and to execute local install scripts, and it relies on raw browser-cookie authentication. This looks more like a risky third-party integration than confirmed malware.

Confidence: 81%Severity: 62%
Audit Metadata
Analyzed At
May 17, 2026, 06:10 AM
Package URL
pkg:socket/skills-sh/Aradotso%2Fmcp-skills%2Flanhu-mcp-collaboration%2F@bad12aa20a57fcca7a905958aa6751cde7fede9c
Security Audit — socket — lanhu-mcp-collaboration