mcp-cli-tool

Warn

Audited by Socket on May 17, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s purpose is coherent, but its footprint is broader and riskier than a simple CLI guide. The main concerns are the third-party `curl|bash` installer, credential forwarding into arbitrary MCP servers, and agent-oriented automation that can execute external tools and process untrusted remote content. Not confirmed malware, but medium-high supply-chain and credential-handling risk.

Confidence: 82%Severity: 74%
Audit Metadata
Analyzed At
May 17, 2026, 11:31 AM
Package URL
pkg:socket/skills-sh/Aradotso%2Fmcp-skills%2Fmcp-cli-tool%2F@63415f179693ddbb81594a1513f76f08561275da
Security Audit — socket — mcp-cli-tool